JanielDary / ELFieScanner
A C++ tool for process memory scanning & suspicious telemetry generation that attempts to detect a number of malicious techniques used by threat actors & those which have been incorporated into open-source user-mode rootkits.
☆79Updated 8 months ago
Alternatives and similar repositories for ELFieScanner:
Users that are interested in ELFieScanner are comparing it to the libraries listed below
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆71Updated 4 months ago
- Cheat sheet to detect and remove linux kernel rootkit☆47Updated last month
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆41Updated 5 years ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆43Updated 8 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 9 months ago
- ☆104Updated 3 months ago
- ☆17Updated this week
- Windows Administrator level Implant.☆48Updated 4 months ago
- CVE-2024-30090 - LPE PoC☆103Updated 3 months ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆48Updated 4 months ago
- ☆56Updated last month
- Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation☆125Updated 10 months ago
- Collection of codes focused on Linux rootkits☆78Updated this week
- "Service-less" driver loading☆150Updated 2 months ago
- A project that demonstrates embedding shellcode payloads into image files (like PNGs) using Python and extracting them using C/C++. Paylo…☆59Updated 2 weeks ago
- ☆57Updated 10 months ago
- Stage 0☆148Updated last month
- A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.☆109Updated 10 months ago
- Malware Analysis tools☆25Updated 4 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 9 months ago
- ☆49Updated 3 months ago
- Monarch - The Adversary Emulation Toolkit☆61Updated 3 weeks ago
- ☆111Updated last month
- Tools for analyzing EDR agents☆218Updated 7 months ago
- SRE - Dissecting Malware for Static Analysis & the Complete Command-line Tool☆51Updated last month
- ☆112Updated last year
- Small toolkit for extracting information and dumping sensitive strings from Windows processes☆107Updated 6 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆68Updated 3 weeks ago
- ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Sysc…☆115Updated 4 months ago