MandConsultingGroup / ring3-kit
Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)
☆76Updated 2 years ago
Alternatives and similar repositories for ring3-kit
Users that are interested in ring3-kit are comparing it to the libraries listed below
Sorting:
- PoC Thread Execution Hijacking for Win32 Code Injection☆176Updated 9 months ago
- 64bit Windows 10 shellcode that adds user BOKU:SP3C1ALM0V3 to the system and the localgroups Administrators & "Remote Desktop Users"☆40Updated 4 years ago
- Collection of source code for Polymorphic, Metamorphic, and Permutation Engines used in Malware☆27Updated 5 years ago
- Hellokitty Ransomware Source Code☆15Updated last year
- NT AUTHORITY\SYSTEM☆39Updated 4 years ago
- Zero-Day Code Injection and Persistence Technique☆33Updated 8 years ago
- Shellcodev is a tool designed to help and automate the process of shellcode creation.☆109Updated last year
- Gozi ISFB is a well-known and widely distributed banking trojan, and has been in the threat landscape for the past several years.☆64Updated 7 years ago
- APT, Cyber warfare, Penetration testing, Zero-day,Exploiting,Fuzzing,Privilege-Escalation,browser-security,Spyware,Malwres evade…☆35Updated 6 years ago
- Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/☆37Updated 3 years ago
- Alleged source code leak of Osiris banking trojan☆37Updated 4 years ago
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆71Updated 3 years ago
- A tool to teleport shellcode to victim's device without triggering IDS or AV 100% FUD☆15Updated 2 years ago
- Small attempt at a decent Import Address Table (IAT) Dumper☆15Updated 8 months ago
- A Simple AES Command Line Crypter☆36Updated 2 years ago
- Windows GPU rootkit PoC by Team Jellyfish☆35Updated 10 years ago
- Overwrite MBR and add own custom message☆17Updated 5 years ago
- simple user-mode Rootkit☆104Updated 2 years ago
- Process Hollowing demonstration & explanation☆35Updated 4 years ago
- Hiding your process in ProcessHacker,Task Manager,etc by patching NtQuerySystemInformation☆87Updated 4 years ago
- C++ Multi-Stage Semi-Polymorphic Malware Loader.☆9Updated 3 years ago
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Updated 3 years ago
- XssBot-Модульный резидентный бот с супер админкой☆11Updated 2 years ago
- ☆13Updated 4 years ago
- A simple example on how to initiate a direct syscall on WoW64☆11Updated 7 years ago
- Bypassing windows uac, however its an old approach/method but its still unpatched ¯\_(ツ)_/¯☆44Updated 3 years ago
- improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys☆50Updated 2 years ago
- Simple PE Packer Which Encrypts .text Section☆50Updated 7 years ago
- POC Ring3 Windows Rootkit (x86 / x64) - Hide processes and files☆54Updated last year
- Packer (actually a crypter) for antivirus evasion implemented for windows PE files (BSc-Thesis)☆104Updated 4 years ago