MatheuZSecurity / UnhookingLinuxEdrLinks
Attacking the cleanup_module function of a kernel module
☆52Updated 4 months ago
Alternatives and similar repositories for UnhookingLinuxEdr
Users that are interested in UnhookingLinuxEdr are comparing it to the libraries listed below
Sorting:
- Windows AppLocker Driver (appid.sys) LPE☆67Updated last year
- Linux Sleep Obfuscation☆105Updated last year
- CVE-2024-30090 - LPE PoC☆108Updated last year
- Slides for COM Hijacking AV/EDR Talk on 38c3☆74Updated 10 months ago
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆53Updated 5 months ago
- e(X)tensiable (Rust) Malware Toolkit: (Soon!) Full Featured Rust C2 Framework with Awesome Features!☆25Updated last year
- ☆59Updated last year
- Plantronics Desktop Hub LPE☆37Updated last year
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆50Updated 9 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆105Updated last year
- Identifies LOLDrivers that are not blocked by the active HVCI policy — ideal for BYOVD scenarios.☆30Updated 2 months ago
- Template-based generation of shellcode loaders☆79Updated last year
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆130Updated 7 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆88Updated last year
- Select any exported function in a dll as the new dll's entry point.☆81Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆36Updated 3 years ago
- Standalone Metasploit-like XOR encoder for shellcode☆50Updated last year
- ☆37Updated 2 years ago
- API Hammering with C++20☆49Updated 3 years ago
- various methods of making API calls☆19Updated 9 months ago
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆45Updated last year
- ☆81Updated last year
- ☆80Updated last year
- A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.☆111Updated last year
- ☆60Updated 6 months ago
- Win32 keylogger that supports all (non-ime using) languages correctly☆52Updated last year
- A synergized Visual Studio and Rust development environment☆19Updated 9 months ago
- A more reliable way of resolving syscall numbers in Windows☆52Updated last year
- Folder Or File Delete to Get System Shell on Current Session Desktop☆47Updated 10 months ago
- ☆72Updated 3 months ago