NUL0x4C / GP
using the gpu to hide your payload
☆53Updated 2 years ago
Alternatives and similar repositories for GP:
Users that are interested in GP are comparing it to the libraries listed below
- API Hammering with C++20☆44Updated 2 years ago
- An initial proof of concept of a bootkit based on Cr4sh's DMABackdoorBoot☆61Updated last year
- 🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python☆42Updated 10 months ago
- Reimplementation of the KExecDD DSE bypass technique.☆45Updated 4 months ago
- Splitting and executing shellcode across multiple pages☆99Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys☆49Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated 11 months ago
- abusing Process Hacker driver to terminate other processes (BYOVD)☆81Updated last year
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- Get your data from the resource section manually, with no need for windows apis☆56Updated 3 months ago
- Piece of code to detect and remove hooks in IAT☆62Updated 2 years ago
- A proof of concept I developed to improve Gargoyle back in 2018 to achieve true memory obfuscation from position independent code☆43Updated 4 months ago
- Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).☆135Updated 2 years ago
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- Artemis - C++ Hell's Gate Syscall Implementation☆31Updated last year
- Various methods of executing shellcode☆70Updated last year
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 8 months ago
- ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption☆81Updated last year
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- Small PoC of using a Microsoft signed executable as a lolbin.☆133Updated last year
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆48Updated 2 years ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆41Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 6 months ago
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆105Updated 4 months ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆122Updated 2 years ago
- Rusty Hell's Gate / Halo's Gate / Tartarus' Gate / FreshyCalls / Syswhispers2 Library☆25Updated 2 years ago
- A Bumblebee-inspired Crypter☆80Updated 2 years ago
- ☆36Updated last year
- Minifilter Callback Patching Proof-of-Concept☆64Updated 2 years ago