MatheuZSecurity / RingReaperLinks
Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.
☆73Updated this week
Alternatives and similar repositories for RingReaper
Users that are interested in RingReaper are comparing it to the libraries listed below
Sorting:
- ☆55Updated 8 months ago
- A lightweight tool that injects a custom assembly proxy into a target process to silently bypass AMSI scanning by redirecting AmsiScanBuf…☆41Updated last month
- ☆36Updated 7 months ago
- Folder Or File Delete to Get System Shell on Current Session Desktop☆40Updated 5 months ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆61Updated 5 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆82Updated 8 months ago
- Early cascade injection PoC based on Outflanks blog post written in Rust☆54Updated 5 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆89Updated last year
- Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.☆80Updated last month
- ☆81Updated last year
- A simple C++ Windows tool to get information about processes exposing named pipes.☆38Updated 4 months ago
- command control framework☆21Updated 3 weeks ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆43Updated 11 months ago
- POC of GITHUB simple C2 in rust☆53Updated 5 months ago
- ☆82Updated last year
- Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)☆29Updated 5 months ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆49Updated 5 months ago
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆74Updated 2 months ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆33Updated last year
- ☆30Updated 3 months ago
- Create Anti-Copy DRM Malware☆59Updated 10 months ago
- Section-based payload obfuscation technique for x64☆61Updated 11 months ago
- ☆22Updated 4 months ago
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆42Updated last year
- Go Shellcode Loader to be Integrated in Exploration C2☆27Updated 5 months ago
- remote process injections using pool party techniques☆63Updated 2 weeks ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆54Updated 6 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 9 months ago
- A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user☆40Updated 10 months ago
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆49Updated 2 months ago