EvilBytecode / Ntdll-Unhook
Unhook Ntdll.dll, Go & C++.
☆11Updated 2 months ago
Related projects: ⓘ
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.☆15Updated last month
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆20Updated this week
- ☆14Updated this week
- A simple rpc2socks alternative in pure Go.☆23Updated 2 months ago
- This exploit is utilising AddressOfEntryPoint of process which is RX and using WriteProcessMemory internal magic to change the permission…☆12Updated last month
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- DFSCoerce exe revisited version with custom authentication☆34Updated 8 months ago
- Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts☆17Updated last year
- C# API for Nidhogg rootkit☆15Updated 4 months ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆30Updated 10 months ago
- ☆25Updated last month
- Creation and removal of Defender path exclusions and exceptions in C#.☆29Updated 10 months ago
- Bunch of BOF files☆21Updated 7 months ago
- A direct improvement to remote TLS Injection.☆15Updated 3 months ago
- shell code example☆10Updated 3 weeks ago
- Command and Control☆23Updated last month
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆32Updated 8 months ago
- Rewrite to fit my needs☆25Updated last month
- ☆47Updated last year
- Parent Process ID Spoofing, coded in CGo.☆21Updated 2 months ago
- .NET port of Leron Gray's azbelt tool.☆26Updated 11 months ago
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆18Updated 11 months ago
- Cobalt Strike Beacon Object File (BOF) that uses CredUIPromptForWindowsCredentials API to invoke credential prompt☆18Updated last year
- ☆27Updated 3 months ago
- Section-based payload obfuscation technique for x64☆59Updated last month
- Extension functionality for the NightHawk operator client☆26Updated 10 months ago
- ☆28Updated this week
- A .NET implementation to dump SAM, SYSTEM, SECURITY registry hives from a remote host☆37Updated 9 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆50Updated 6 months ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 4 months ago