Hamid-K / stalksnetLinks
A few STUXNET samples and live traffic captures from July 2010 while many stuxnet implants were still operational.
☆26Updated 10 months ago
Alternatives and similar repositories for stalksnet
Users that are interested in stalksnet are comparing it to the libraries listed below
Sorting:
- ☆19Updated 2 months ago
- Permanently disable EDRs as local admin☆92Updated last month
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆21Updated 7 months ago
- ☆107Updated 9 months ago
- Windows Administrator level Implant.☆50Updated 10 months ago
- ☆64Updated last year
- ☆39Updated 5 months ago
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆40Updated 9 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆69Updated 5 months ago
- ☆49Updated 4 months ago
- Proof-of-concept modular implant platform leveraging v8☆54Updated 5 months ago
- ☆57Updated 3 months ago
- Demoting PPL anti-malware services to less than a guest user☆64Updated 6 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 5 years ago
- Exfiltrate data over audio output from remote desktop sessions - Covert channel PoC☆61Updated 8 months ago
- Lena's scripts/code/resources for malware analysis☆27Updated last year
- ☆37Updated 8 months ago
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆37Updated 5 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆89Updated last year
- POC of GITHUB simple C2 in rust☆53Updated 2 weeks ago
- Mythic C2 wrapper for NimSyscallPacker☆25Updated 4 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆113Updated 11 months ago
- ☆67Updated 6 months ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆42Updated last year
- ☆28Updated last year
- Enable or Disable TokenPrivilege(s)☆14Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Updated 2 years ago
- A more reliable way of resolving syscall numbers in Windows☆53Updated last year
- .NET tool used to enrich RPC telemetry☆95Updated last month