Proof-of-Concept code snippets for a variety of different process injection techniques
☆23Feb 2, 2023Updated 3 years ago
Alternatives and similar repositories for ProcessInjectionPOCs
Users that are interested in ProcessInjectionPOCs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated last year
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated 10 months ago
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆13Jul 15, 2023Updated 3 years ago
- ☆14Jul 26, 2025Updated last year
- It's what all the kids are talking about☆12Apr 25, 2023Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Better version of SharpPick☆14Aug 29, 2025Updated 10 months ago
- Command line & PPID spoofing☆31Apr 15, 2023Updated 3 years ago
- A logging ASKPASS binary☆29May 29, 2020Updated 6 years ago
- Havoc plugin allowing in-memory execution of PowerShell cmdlets☆14Dec 14, 2023Updated 2 years ago
- A nim port of C5pider's Ekko project.☆18Oct 1, 2022Updated 3 years ago
- Standalone Go implementation of Metasploit's "db_nmap" and "db_import" commands.☆19Nov 6, 2024Updated last year
- Extracts TEXT section of a PE, ELF, or Mach-O executable to shellcode☆107May 5, 2023Updated 3 years ago
- Matryoshka loader is a tool that red team operators can leverage to generate shellcode for Microsoft Office document phishing payloads.☆43May 24, 2021Updated 5 years ago
- ☆11Aug 10, 2021Updated 4 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A small example of loading BOFs in Python with pure reflection☆19Jan 26, 2023Updated 3 years ago
- ☆13Sep 29, 2025Updated 9 months ago
- A Rust crate for parsing Windows user minidumps.☆42May 13, 2026Updated 2 months ago
- Active Directory Enumeration and Exploitation☆13Jul 15, 2026Updated last week
- Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or…☆42Dec 22, 2025Updated 7 months ago
- ☆14Dec 5, 2024Updated last year
- Little java tool to decrypt passwords from Openfire embedded-db☆16Nov 14, 2015Updated 10 years ago
- Caddy v2 module to filter requests based on C2 profiles☆46Apr 24, 2025Updated last year
- Remove API hooks from a Beacon process.☆77Mar 13, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆118Jan 20, 2025Updated last year
- A Lua module made to solve for the roots of quadratic, cubic and quartic functions.☆12Nov 12, 2019Updated 6 years ago
- Small utility package for manipulating Windows process tokens☆24Apr 26, 2022Updated 4 years ago
- A PoC .NET-specific process injection tool☆58Mar 17, 2024Updated 2 years ago
- The code I write in my blog☆115Jun 27, 2026Updated 3 weeks ago
- Shikata ga nai (仕方がない) encoder ported into go with several improvements☆32Jan 28, 2026Updated 5 months ago
- ☆39Aug 6, 2025Updated 11 months ago
- Resolve WinAPI func. Custom GetProcAddress and GetModuleHandle written in Nim☆33Jun 2, 2021Updated 5 years ago
- D/Invoke standalone shellcode runners☆40Nov 23, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated last year
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- ☆20Jul 2, 2021Updated 5 years ago
- Fully automated windows credentials dumper, for SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with…☆80Nov 18, 2024Updated last year
- a port of privkit bof for havoc☆25Dec 8, 2023Updated 2 years ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆23Aug 27, 2022Updated 3 years ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated 11 months ago