EvilBytecode / PPID-Spoofing
Parent Process ID Spoofing, coded in CGo.
☆22Updated 7 months ago
Alternatives and similar repositories for PPID-Spoofing:
Users that are interested in PPID-Spoofing are comparing it to the libraries listed below
- Unix Process hollowing in rust☆20Updated 2 months ago
- Malware development in Go, learn today, anti dynamic analysis & Static & sandboxes.☆11Updated 7 months ago
- Unhook Ntdll.dll, Go & C++.☆18Updated 7 months ago
- Golang Implementation of Hell's gate☆17Updated last year
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.☆18Updated 6 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 5 months ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆30Updated last year
- ☆17Updated 2 months ago
- DFSCoerce exe revisited version with custom authentication☆38Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆41Updated 6 months ago
- A simple rpc2socks alternative in pure Go.☆28Updated 7 months ago
- ☆52Updated 3 months ago
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- A simple website to act as a store for havoc modules and extensions☆25Updated last month
- BOF for C2 framework☆39Updated 3 months ago
- e(X)tensiable (Rust) Malware Toolkit: (Soon!) Full Featured Rust C2 Framework with Awesome Features!☆23Updated 6 months ago
- Dump Linux keyrings☆16Updated 7 months ago
- ☆47Updated last year
- ☆18Updated 4 months ago
- A pure C version of SymProcAddress☆25Updated 11 months ago
- Mythic C2 wrapper for NimSyscallPacker☆21Updated 2 months ago
- Items related to the RedELK workshop given at security conferences☆28Updated last year
- ☆28Updated 8 months ago
- A C# port of https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80☆19Updated last year
- Deobfuscation of XorStringsNet☆12Updated 3 months ago
- Create PDFs with HTML smuggling attachments that save on opening the document.☆29Updated last year