MastMind / PE-infector
Crossplatform tool for inject shellcode into .exe and .dll binaries (x86 and x64)
☆53Updated 6 months ago
Related projects ⓘ
Alternatives and complementary repositories for PE-infector
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated 9 months ago
- DLL Exports Extraction BOF with optional NTFS transactions.☆78Updated 3 years ago
- ☆44Updated 2 years ago
- An attempt to make a LoadLibrary designed for offensive operations, in C# obviously.☆53Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- API Hammering with C++20☆34Updated 2 years ago
- ☆12Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- Artemis - C++ Hell's Gate Syscall Implementation☆30Updated last year
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆39Updated 11 months ago
- abusing Process Hacker driver to terminate other processes (BYOVD)☆79Updated last year
- A method to execute shellcode using RegisterWaitForInputIdle API.☆51Updated last year
- ☆35Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- A (quite) simple steganography algorithm to hide shellcodes within bitmap image.☆21Updated 6 months ago
- Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules☆42Updated last year
- ☆53Updated 2 years ago
- a library that automates some clean syscalls to make it easier to implement☆82Updated 2 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆32Updated last year
- Get your data from the resource section manually, with no need for windows apis☆53Updated last month
- Inject shellcode into process via "EarlyBird"☆24Updated 3 years ago
- Persistence via Shell Extensions☆62Updated last year
- EmbedExeLnk by x86matthew modified by d4rkiZ☆29Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Sleep Obfuscation☆41Updated 2 years ago