Meowmycks / catdumperLinks
LSASS Credential Dumper that utilizes the Windows API, in-memory RC4 encryption and Base64 encoding, and HTTPS exfiltration.
☆10Updated last year
Alternatives and similar repositories for catdumper
Users that are interested in catdumper are comparing it to the libraries listed below
Sorting:
- ☆12Updated 2 years ago
- AIDA64DRIVER Elevation of Privilege Vulnerability☆14Updated 8 months ago
- Bypass Userland EDR hooks by Loading Reflective Ntdll in memory from a remote server based on Windows ReleaseID to avoid opening a handle…☆15Updated 2 years ago
- Self Delete DLL☆23Updated last year
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆19Updated 2 years ago
- ☆18Updated 9 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 9 months ago
- A BOF for enumerating version information for DLLs associated for a Beacon process.☆15Updated 3 years ago
- CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation☆20Updated 2 years ago
- Just another Process Injection using Process Hollowing technique.☆17Updated last year
- Evilbytecode-Gate resolves Windows System Service Numbers (SSNs) using two methods: analyzing the Guard CF Table in ntdll.dll and parsing…☆22Updated 2 months ago
- Encrypted shellcode injector with basic virtual machine evasion using C++☆9Updated 3 years ago
- Execute Remote Assembly with args passing and with AMSI and ETW patching☆11Updated 2 years ago
- ☆13Updated 2 years ago
- Giga-byte Control Center (GCC) is a software package designed for improved user experience of Gigabyte hardware, often found in gaming an…☆31Updated 2 years ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 7 months ago
- A simple BOF that disables some logging with NtSetInformationProcess☆13Updated last year
- Remap ntdll.dll using only NTAPI functions with a suspended process☆21Updated 3 months ago
- A lexer and parser for Sleep☆20Updated 2 months ago
- Misery Loader to bypass modern EDR solutions☆11Updated 6 months ago
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆28Updated 2 years ago
- A tracker DLL which enables 'NTAPI->Syscall' tracking whenever it is loaded. It calls 'NtSetInformationProcess' API call with a callback …☆12Updated 8 months ago
- Enumerate SSN (System Service Numbers or Syscall ID) and syscall instruction address in ntdll module by parsing the PEB of the current pr…☆21Updated last year
- really ?☆12Updated last year
- An improvement and a different approach to Mockingjay Self-Injection.☆35Updated last year
- ☆19Updated 2 years ago
- Obfuscate payloads using IPv4, IPv6, MAC or UUID strings☆20Updated last year
- A utility that can be used to launch an executable with a DLL injected☆20Updated last year
- Dangling COM Keys Finder☆17Updated 3 years ago
- Self delete DLL (2)☆14Updated last year