ArtemBaranov / WindowsRootkitsGuide
☆55Updated 3 weeks ago
Alternatives and similar repositories for WindowsRootkitsGuide:
Users that are interested in WindowsRootkitsGuide are comparing it to the libraries listed below
- ☆102Updated 2 months ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 5 months ago
- Analyse MSI files for vulnerabilities☆121Updated 4 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆131Updated last year
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 9 months ago
- Shellcode encryptor using a substitution cipher with a randomly generated key.☆108Updated last month
- Windows Administrator level Implant.☆48Updated 3 months ago
- "Service-less" driver loading☆147Updated last month
- ☆84Updated 2 years ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆48Updated 4 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆46Updated 8 months ago
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆41Updated 5 years ago
- ☆136Updated last month
- This comprehensive and central repository is designed for cybersecurity enthusiasts, researchers, and professionals seeking to stay ahead…☆87Updated 2 months ago
- Tools for analyzing EDR agents☆214Updated 7 months ago
- A Mythic Agent written in PIC C.☆167Updated last week
- ☆111Updated last month
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆71Updated 4 months ago
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆152Updated last month
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 4 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆64Updated 2 months ago
- This project is an implant framework designed for long term persistent access to Windows machines.☆111Updated last year
- Lena's scripts/code/resources for malware analysis☆25Updated 7 months ago
- 32bit MIPS I VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆103Updated last month
- ☆36Updated 9 months ago
- Virus.xcheck is a Python tool designed to bulk verify the existence of file hashes in the Virus Exchange database and fetch download URLs…☆49Updated last year
- ☆20Updated last year
- ☆112Updated 11 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆84Updated 11 months ago