Nariod / ronflexLinks
Attempts to suspend all known AV/EDRs processes on Windows using syscalls and the undocumented NtSuspendProcess API. Made with <3 for pentesters. Written in Rust.
☆13Updated 2 years ago
Alternatives and similar repositories for ronflex
Users that are interested in ronflex are comparing it to the libraries listed below
Sorting:
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆39Updated 2 years ago
- ☆59Updated last year
- an Improoved Version of 0xNinjaCyclone´s EarlyCascade Code☆19Updated 4 months ago
- Rust Implementation of SharpDllProxy for DLL Proxying Technique☆30Updated 2 years ago
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆63Updated 6 months ago
- A repository with my code snippets for research/education purposes.☆50Updated last year
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated 2 years ago
- PhantomsGate: Advanced Shellcode Injection Technique☆23Updated last year
- A collection of source code, binaries, and compilation scripts designed to bypass detection☆25Updated 2 years ago
- Small project to facilitate creation of .lnk payloads☆70Updated 2 years ago
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆51Updated 2 years ago
- Event Tracing for Windows EDR bypass in Rust (usermode)☆27Updated last year
- Erebus is a payload generator written in Nim.☆16Updated 2 years ago
- Create PDFs with HTML smuggling attachments that save on opening the document.☆30Updated 2 weeks ago
- Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog …☆82Updated last year
- Rust in-memory dumper☆108Updated last year
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆33Updated last week
- Donut generator in rust.☆27Updated 3 years ago
- Reverse TCP Powershell has never been this paranoid. (basically an Opsec-safe reverse powershell)☆30Updated 3 years ago
- UAC Bypass using CMSTP in Rust☆29Updated 7 months ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆85Updated 2 years ago
- Just another ntdll unhooking using Parun's Fart technique☆75Updated 2 years ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 7 months ago
- Duplicate not owned Token from Running Process☆72Updated last year
- in-process powershell runner for BRC4☆45Updated last year
- PowerShell script to terminate protected processes such as anti-malware and EDRs.☆27Updated 2 years ago
- Public repo of some woking evilginx phishlets☆36Updated 8 months ago
- Cortex EDR Ransomware protection Bypass☆24Updated 5 months ago
- malleable profile generator GUI for Havoc☆55Updated 2 years ago
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆41Updated last year