MaorSabag / Paruns-Fart
Just another ntdll unhooking using Parun's Fart technique
☆74Updated 2 years ago
Alternatives and similar repositories for Paruns-Fart:
Users that are interested in Paruns-Fart are comparing it to the libraries listed below
- ☆48Updated last year
- ☆35Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 8 months ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆42Updated last year
- ☆59Updated last year
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- Tool for playing with Windows Access Token manipulation.☆54Updated 2 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆79Updated 2 years ago
- Lateral Movement via the .NET Profiler☆80Updated 4 months ago
- Rewrite to fit my needs☆27Updated 8 months ago
- Section-based payload obfuscation technique for x64☆59Updated 7 months ago
- ☆28Updated 7 months ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆69Updated 10 months ago
- malleable profile generator GUI for Havoc☆56Updated last year
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- ☆52Updated 2 months ago
- Bunch of BOF files☆30Updated 3 months ago
- My implementation of Halo's Gate technique in C#☆54Updated 2 years ago
- early cascade injection PoC based on Outflanks blog post, in rust☆56Updated 4 months ago
- Click Once + App Domain☆62Updated last year
- ☆108Updated 4 months ago
- A care package of useful bofs for red team engagments☆54Updated 3 months ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆21Updated 2 years ago
- Find DLLs with RWX section☆78Updated last year
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆82Updated 2 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆80Updated 5 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆48Updated last year