☆84Aug 26, 2024Updated 2 years ago
Alternatives and similar repositories for process-enumeration-stealth
Users that are interested in process-enumeration-stealth are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- It stinks☆101Apr 22, 2022Updated 4 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆116Feb 27, 2021Updated 5 years ago
- Custom implementation of DbgHelp's MiniDumpWriteDump function. Uses static syscalls to replace low-level functions like NtReadVirtualMemo…☆128Jan 18, 2022Updated 4 years ago
- A small example of loading BOFs in Python with pure reflection☆19Jan 26, 2023Updated 3 years ago
- My experience using Windows API for offensive purposes☆17Jul 10, 2021Updated 5 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆104Oct 7, 2023Updated 2 years ago
- ☆23May 28, 2021Updated 5 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆286Sep 18, 2024Updated last year
- Evasive Process Hollowing Techniques☆144Aug 16, 2020Updated 6 years ago
- This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret …☆268Apr 29, 2023Updated 3 years ago
- A way to delete a locked file, or current running executable, on disk.☆620Nov 5, 2025Updated 9 months ago
- List the ETW provider(s) in the registration table of a process.☆81Sep 20, 2023Updated 2 years ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆66Mar 19, 2024Updated 2 years ago
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆124May 22, 2021Updated 5 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging☆586Mar 8, 2024Updated 2 years ago
- Antivirus Emulator Fingerprints☆30Oct 12, 2018Updated 7 years ago
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆273May 3, 2023Updated 3 years ago
- KaynLdr is a Reflective Loader written in C/ASM☆552Dec 3, 2023Updated 2 years ago
- NINA: No Injection, No Allocation x64 Process Injection Technique☆225Jun 9, 2020Updated 6 years ago
- Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs☆125May 24, 2022Updated 4 years ago
- Using fibers to run in-memory code.☆245Oct 19, 2023Updated 2 years ago
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆114May 21, 2023Updated 3 years ago
- A bunch of scripts and code i wrote.☆155Nov 7, 2024Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Use hardware breakpoints to spoof the call stack for both syscalls and API calls☆206Jun 6, 2024Updated 2 years ago
- Self Delete DLL☆22Feb 15, 2024Updated 2 years ago
- Beacon Object File Loader☆294Dec 3, 2023Updated 2 years ago
- A more stealthy variant of "DLL hollowing"☆368Mar 8, 2024Updated 2 years ago
- PoC for hiding PE exports☆67Dec 19, 2020Updated 5 years ago
- EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and e…☆291Mar 8, 2023Updated 3 years ago
- miscellaneous codes☆38Sep 24, 2023Updated 2 years ago
- Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR☆157Jul 22, 2021Updated 5 years ago
- In-memory token vault BOF for Cobalt Strike☆151Aug 18, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- An example reference design for a proposed BOF PE☆245Jan 23, 2026Updated 7 months ago
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆143Sep 12, 2022Updated 3 years ago
- Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven☆270Oct 16, 2024Updated last year
- a modified CONTEXT based ropchain to circumvent CFG-FindHiddenShellcode and EtwTi-FluctuationMonitor☆110Mar 25, 2024Updated 2 years ago
- "Service-less" driver loading☆192Nov 28, 2024Updated last year
- Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted fi…☆700Mar 11, 2024Updated 2 years ago
- Load and execute COFF files and Cobalt Strike BOFs in-memory☆228Sep 13, 2022Updated 3 years ago