EgeBalci / crc32_apiLinks
Assembly API block that uses CRC32 for resolving Windows API function addresses
☆18Updated 2 years ago
Alternatives and similar repositories for crc32_api
Users that are interested in crc32_api are comparing it to the libraries listed below
Sorting:
- Assembly block for finding and calling the windows API functions inside import address table(IAT) of the running PE file.☆80Updated 2 years ago
- Assembly block for hooking windows API functions.☆94Updated 6 years ago
- Read Memory without ReadProcessMemory for Current Process☆89Updated 3 years ago
- ☆65Updated 3 years ago
- A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original…☆97Updated 6 years ago
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆67Updated 3 years ago
- ☆39Updated 2 years ago
- A Poc on blocking Procmon from monitoring network events☆111Updated 6 months ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆57Updated last week
- ☆90Updated last year
- POC of PPID spoofing using NtCreateUserProcess with syscalls to create a suspended process and performing process injection by overwritti…☆40Updated 4 years ago
- ☆118Updated 3 years ago
- CSharp Writeups for HackSys Extreme Vulnerable Driver☆45Updated 4 years ago
- Enabled / Disable LSA Protection via BYOVD☆81Updated 4 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆115Updated 4 years ago
- ☆38Updated 2 years ago
- Clone running process with ZwCreateProcess☆59Updated 5 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆31Updated 3 years ago
- A Study in Obfuscation: Analyzing the effect of various techniques to bypass AV engines☆45Updated 3 years ago
- Files for http://deniable.org/windows/windows-callbacks☆26Updated 5 years ago
- ☆62Updated 4 years ago
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆66Updated 2 years ago
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆107Updated 5 years ago
- ☆60Updated 3 years ago
- ☆15Updated 5 years ago
- ☆70Updated last year
- Detours implementation (x64/x86) which used only ntdll import☆90Updated 3 months ago
- A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.☆71Updated 3 years ago
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆70Updated 4 years ago
- Process Hollowing demonstration & explanation☆35Updated 4 years ago