Ap3x / WALKWHISPER
Windows API header file parsing tool to generate source code for Windows API hashing
☆4Updated last year
Alternatives and similar repositories for WALKWHISPER:
Users that are interested in WALKWHISPER are comparing it to the libraries listed below
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆53Updated 2 years ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆36Updated 2 years ago
- Installing wazuh SIEM Unified XDR and SIEM protection☆21Updated 3 weeks ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- malleable profile generator GUI for Havoc☆56Updated last year
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆58Updated last year
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 8 months ago
- ☆58Updated last year
- Slide decks and/or materials from conference presentations☆55Updated 2 years ago
- quASAR: ASAR manipulation made easy☆24Updated 2 years ago
- Attack chain emulator. Write recipes for initial access easily☆20Updated last year
- ☆47Updated last year
- Unchain AMSI by patching the provider’s unmonitored memory space☆88Updated 2 years ago
- A more reliable way of resolving syscall numbers in Windows☆50Updated 11 months ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆20Updated 2 years ago
- Lifetime AMSI bypass.☆35Updated 7 months ago
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated 11 months ago
- maldev obviously☆25Updated 7 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 9 months ago
- ☆29Updated last month
- ☆38Updated 2 years ago
- Nim process hollowing loader☆49Updated 5 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- A tool for carrying out brute force attacks against Office 365, with built in IP rotation use AWS gateways.☆74Updated 7 months ago
- Python module for running BOFs☆64Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- idk man this was the default github name☆35Updated last year