Helixo32 / DetectHooksLinks
Detect userland hooks placed by AV/EDR
☆28Updated 2 years ago
Alternatives and similar repositories for DetectHooks
Users that are interested in DetectHooks are comparing it to the libraries listed below
Sorting:
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- ☆61Updated 2 years ago
- malleable profile generator GUI for Havoc☆55Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated last year
- ☆44Updated last year
- in-process powershell runner for BRC4☆48Updated 2 years ago
- ☆49Updated 2 years ago
- Scripts to interact with Microsoft Graph APIs☆44Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆88Updated 3 years ago
- Quick and dirty PowerShell script to abuse the overly permissive capabilities of the SYSTEM user in a child domain on the Public Key Serv…☆29Updated 2 years ago
- ☆52Updated last year
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆37Updated last month
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 3 years ago
- ☆47Updated 2 years ago
- Remote Template Injection Toolkit☆46Updated last year
- Sniffing files generator☆59Updated 10 months ago
- ☆29Updated 2 years ago
- ☆36Updated 2 years ago
- ☆64Updated last year
- ☆38Updated 9 months ago
- ☆53Updated 2 years ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆23Updated 3 years ago
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆31Updated 3 years ago
- ☆59Updated last year
- This repo hosts a poc of how to execute F# code within an unmanaged process☆70Updated last year
- A pure C version of SymProcAddress☆30Updated last year
- Python module for running BOFs☆79Updated last month
- ☆38Updated 2 years ago
- Find DLLs with RWX section☆80Updated 2 years ago