Maldev-Academy / TrapFlagForSyscallingLinks
Bypass user-land hooks by syscall tampering via the Trap Flag
☆22Updated this week
Alternatives and similar repositories for TrapFlagForSyscalling
Users that are interested in TrapFlagForSyscalling are comparing it to the libraries listed below
Sorting:
- One-header configurable C++20 COFF loader☆21Updated last month
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆63Updated last year
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆42Updated last year
- Heap encryption in Nim☆19Updated last year
- Shellcode Loader Utilizing ETW Events☆65Updated 5 months ago
- ☆16Updated this week
- A collection of position independent coding resources☆92Updated 6 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆17Updated 3 years ago
- Hunting and injecting RWX 'mockingjay' DLLs in pure nim☆59Updated 8 months ago
- ☆88Updated last year
- Rust template/library for implementing your own COFF loader☆69Updated 6 months ago
- A process injection technique using only thread context manipulation☆37Updated last year
- a demo module for the kaine agent to execute and inject assembly modules☆39Updated 11 months ago
- Proxy function calls through the thread pool with ease☆28Updated 5 months ago
- ☆40Updated 8 months ago
- A 64 bit executable junk code engine for polymorphic malware.☆65Updated 2 months ago
- shell code example☆62Updated 3 months ago
- Mentally ill EtwTi parser☆65Updated last month
- BOF for C2 framework☆42Updated 9 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆60Updated 9 months ago
- Sample Rust Hooking Engine☆36Updated last year
- Section-based payload obfuscation technique for x64☆64Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆76Updated last year
- macOS dylib stager☆36Updated 7 months ago
- Callstack spoofing using a VEH because VEH all the things.☆23Updated 5 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆26Updated 4 months ago
- Dynamically resolve API function addresses at runtime in a secure manner.☆68Updated 3 months ago
- ☆35Updated 4 months ago
- A Rust crate to parse user-mode minidump files generated on Windows☆15Updated 2 months ago
- Post-Ex BOF tooling for Hannibal☆24Updated 9 months ago