ArtemBaranov / WindowsRootkitsGuide
☆63Updated 2 weeks ago
Alternatives and similar repositories for WindowsRootkitsGuide:
Users that are interested in WindowsRootkitsGuide are comparing it to the libraries listed below
- ☆103Updated 3 months ago
- Lena's scripts/code/resources for malware analysis☆25Updated 8 months ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 6 months ago
- Windows Administrator level Implant.☆48Updated 4 months ago
- Configuration Extractors for Malware☆91Updated 3 weeks ago
- "Service-less" driver loading☆149Updated 2 months ago
- ☆111Updated this week
- Analyse MSI files for vulnerabilities☆124Updated 5 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 5 months ago
- ☆112Updated last year
- NoDelete is a tool that assists in malware analysis by locking a folder where malware drops files before deleting them.☆44Updated last month
- Tools for analyzing EDR agents☆220Updated 8 months ago
- Virus.xcheck is a Python tool designed to bulk verify the existence of file hashes in the Virus Exchange database and fetch download URLs…☆52Updated last year
- ☆36Updated 2 months ago
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆158Updated 2 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆132Updated last year
- ☆143Updated 2 months ago
- A Mythic Agent written in PIC C.☆171Updated 2 weeks ago
- APT hub, It help's research to collect information and data on the latest APT activities. It collects data on APT profiles, IOCs(1 yr), a…☆48Updated 3 months ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆50Updated 5 months ago
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 5 years ago
- ☆18Updated last week
- ☆36Updated 10 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆65Updated 3 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆102Updated 5 months ago
- ☆105Updated 7 months ago
- ☆139Updated 6 months ago