NUL0x4C / FetchPayloadFromDummyFile
Construct the payload at runtime using an array of offsets
☆61Updated 7 months ago
Alternatives and similar repositories for FetchPayloadFromDummyFile:
Users that are interested in FetchPayloadFromDummyFile are comparing it to the libraries listed below
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- ☆48Updated 3 months ago
- ☆122Updated 4 months ago
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 9 months ago
- ☆92Updated 4 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- Windows Thread Pool Injection Havoc Implementation☆28Updated 10 months ago
- Create Anti-Copy DRM Malware☆51Updated 5 months ago
- ☆92Updated 11 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆46Updated 8 months ago
- BOF with Synthetic Stackframe☆103Updated this week
- Just another C2 Redirector using CloudFlare.☆84Updated 8 months ago
- A BOF to enumerate system process, their protection levels, and more.☆113Updated 2 months ago
- Lateral Movement via the .NET Profiler☆77Updated 2 months ago
- ☆106Updated 2 months ago
- Find DLLs with RWX section☆76Updated last year
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆114Updated 3 months ago
- Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks☆77Updated last month
- Do some DLL SideLoading magic☆77Updated last year
- ☆120Updated last year
- ☆87Updated 2 weeks ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆83Updated 7 months ago
- A collection of position independent coding resources☆64Updated last week
- ☆137Updated 6 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆77Updated 3 months ago