Idov31 / talks-and-publicationsView external linksLinks
Released presentations of my talks + code that used during these talks
☆15Sep 5, 2024Updated last year
Alternatives and similar repositories for talks-and-publications
Users that are interested in talks-and-publications are comparing it to the libraries listed below
Sorting:
- PhantomsGate: Advanced Shellcode Injection Technique☆26Jul 15, 2024Updated last year
- MappingInjection via csharp☆40Nov 19, 2021Updated 4 years ago
- A step-by-step walkthrough of how to write a Client and a Driver to communicate with each other and boost the priority of a thread.☆17Dec 12, 2023Updated 2 years ago
- The Swiss army knife of evasion tool that bypasses AMSI, Applocker, and CLM mode simultaneously.☆26Mar 9, 2024Updated last year
- ☆15Feb 9, 2022Updated 4 years ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆35Oct 31, 2023Updated 2 years ago
- Using fibers to execute shellcode in a local process via csharp☆28Jan 2, 2022Updated 4 years ago
- C# API for Nidhogg rootkit☆21Apr 25, 2024Updated last year
- Interactive program for loading AES encrypted shellcode with Dynamic Invocation, and interactive .NET assemblies in memory.☆13Mar 16, 2022Updated 3 years ago
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆20Apr 17, 2023Updated 2 years ago
- A Study in Obfuscation: Analyzing the effect of various techniques to bypass AV engines☆45Oct 27, 2022Updated 3 years ago
- Weaponizing CLRvoyance for Post-Ex .NET Execution☆38Jul 15, 2021Updated 4 years ago
- Simple and sane compression wrapper library.☆19Oct 28, 2022Updated 3 years ago
- Hides processes from the windows task manager using IAT hooking.☆22Mar 30, 2021Updated 4 years ago
- C# loader that copies a chunk at the time of the shellcode in memory, rather that all at once☆23Jul 14, 2022Updated 3 years ago
- This project is created for research into antivirus evasion by unhooking.☆18Sep 2, 2021Updated 4 years ago
- HookDetection☆45Sep 3, 2021Updated 4 years ago
- a demo module for the kaine agent to execute and inject assembly modules☆41Aug 28, 2024Updated last year
- Beacon Debugger☆55Oct 28, 2024Updated last year
- A repository filled with ideas to break/detect direct syscall techniques☆27Apr 21, 2022Updated 3 years ago
- Change hash for a signed pe☆17Jul 18, 2023Updated 2 years ago
- Use TpAllocWork, TpPostWork and TpReleaseWork to execute machine code☆24Mar 13, 2023Updated 2 years ago
- Disassemble bytecodes as MSIL☆18Jul 31, 2021Updated 4 years ago
- A simplified version of DotNetToJScript to create a JScript file which loads a .NET v2 assembly from memory.☆46Mar 1, 2021Updated 4 years ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆53Feb 29, 2024Updated last year
- One gate to all syscalls!☆23Mar 12, 2022Updated 3 years ago
- Modify managed functions from unmanaged code☆53Feb 1, 2024Updated 2 years ago
- Working Set Page Cache side-channel IPC PoC☆68Jan 9, 2019Updated 7 years ago
- Post-Ex BOF tooling for Hannibal☆24Nov 20, 2024Updated last year
- A small shellcode loader library written in C#☆48Dec 21, 2021Updated 4 years ago
- ☆109Oct 29, 2024Updated last year
- A Simple PoC☆22May 24, 2024Updated last year
- This script make any windows compatible with RDP connection☆21Jul 28, 2025Updated 6 months ago
- Registry hive parsing the async way☆25Oct 29, 2025Updated 3 months ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆61Aug 31, 2022Updated 3 years ago
- Purpose-built Red Team network hardware implant made from common components.☆25Mar 18, 2023Updated 2 years ago
- Modified Version of Melkor @FuzzySecurity capable of creating disposable AppDomains in injected processes.☆28Sep 8, 2021Updated 4 years ago
- Windows x64 Process Injection via Ghostwriting with Dynamic Configuration☆29Oct 29, 2021Updated 4 years ago
- Python tool to find vulnerable AD object and generating csv report☆26Jul 4, 2022Updated 3 years ago