Enelg52 / BackpackLinks
Golang packer that use process hollowing
☆18Updated 3 years ago
Alternatives and similar repositories for Backpack
Users that are interested in Backpack are comparing it to the libraries listed below
Sorting:
- A PoC package for hosting the CLR and executing .NET from Go☆77Updated last year
- execute a PE in the address space of another PE aka process hollowing☆59Updated 3 years ago
- Simple PoCs for utilizing Windows syscalls in Go☆16Updated 4 years ago
- Thanks to @d35ha☆13Updated 4 years ago
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆61Updated 4 years ago
- Preventing 3rd Party DLLs from Injecting into your Malware☆25Updated 4 years ago
- Without closing windows defender, to make defender useless by removing its token privileges and lowering the token integrity.☆31Updated 3 years ago
- Process injection techniques written in Go.☆64Updated 2 years ago
- Process Injection Techniques with Golang☆80Updated 5 years ago
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆67Updated last year
- Go implementation of the Heaven's Gate technique☆100Updated 4 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆101Updated 2 years ago
- Exploring in-memory execution of .NET☆139Updated 3 years ago
- Reflectively load PE☆104Updated 5 years ago
- Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.☆61Updated 2 years ago
- It stinks☆102Updated 3 years ago
- Indirect NT syscalls LSASS dumper.☆46Updated 2 years ago
- Titan: A generic user defined reflective DLL for Cobalt Strike☆84Updated 2 years ago
- ☆50Updated 3 years ago
- C++ WinRM API via Reflective DLL☆146Updated 4 years ago
- This project will guide yout to awareness of injection in almost every window API and process.☆25Updated 3 years ago
- Proof of concept SMB C2 using named pipes in Golang☆25Updated 6 years ago
- Explorer Persistence technique : Hijacking cscapi.dll order loading path and writing our malicious dll into C:\Windows\cscapi.dll , when …☆83Updated 2 years ago
- HookDetection☆46Updated 4 years ago
- Unhooks Bit Defender from NTDLL and KERNELBASE using a classic technique.☆56Updated 2 years ago
- Golang implementation of @CCob's C# ThreadlessInject☆31Updated last year
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆48Updated 2 years ago
- Inject shellcode into process via "EarlyBird"☆26Updated 4 years ago
- Using the Windows API to mess with Task Manager in GoLANG☆14Updated 4 years ago
- BOF combination of KillDefender and Backstab☆170Updated 2 years ago