Neo-Maoku / expandTextSection
A tool that expands the size of the text section in a PE file without loss, supporting both 32-bit and 64-bit programs.
☆22Updated 6 months ago
Related projects ⓘ
Alternatives and complementary repositories for expandTextSection
- Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode☆110Updated 5 months ago
- ☆49Updated 3 months ago
- 主要用于隐藏进程真实路径,进程带windows真签名☆75Updated last month
- 免杀计划任务进行权限维持,过主流杀软。 A schtask tool bypass anti-virus☆66Updated 2 years ago
- Red team tool designed for quickly identifying hijackable programs, evading antivirus software, and EDR (Endpoint Detection and Response)…☆59Updated 6 months ago
- 一种通过进程注入实现强制关闭部分杀软进程的方法(以360安全 卫士和360杀毒为例)☆119Updated 10 months ago
- Magical obfuscator, supports obfuscating EXE, BOF, and ShellCode.☆82Updated this week
- 白文件patch☆13Updated 3 months ago
- SysWhispers3WinHttp 基于SysWhispers3项目增添WinHttp分离加载功能并使用32位GCC进行编译,文件大小14KB,可免杀绕过360核晶防护与Defender☆30Updated last year
- Binary Hollowing☆55Updated 2 months ago
- 一款集成了DLL-Session0注入,APC注入,映射注入,线程劫持,函数踩踏,提权的工具(支持BIN加解密)☆121Updated 3 months ago
- XOR 加密 分离免杀☆64Updated 11 months ago
- 使用 rust 实现 CobaltStrike 的 beacon || Using Rust to implement CobaltStrike's Beacon☆79Updated 2 weeks ago
- This is a third party agent for Havoc C2 written in golang.☆56Updated 10 months ago
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆92Updated 3 weeks ago
- 基于个人习惯使用C/C++的shellcode开发项目模板☆19Updated 3 months ago
- Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.☆16Updated 3 weeks ago
- 使用Visral Studio开发ShellCode☆160Updated last year
- 通过C/C++实现的 Windows RID Hijacking persistence technique (RID劫持 影子账户 账户克隆).☆75Updated 2 years ago
- 天问之路☆26Updated last week
- 通杀检测 基于白文件patch黑代码的免杀技术的后门☆101Updated 3 months ago
- 重构Beacon☆141Updated 3 months ago
- more conveniently Visual-Studio-BOF-template☆53Updated last year
- 白加黑的快速生成器(针对IAT类型)☆93Updated 2 years ago
- 简单致盲火绒Sysdiag杀毒软件☆25Updated 5 months ago
- Cobalt Strike 二开项目☆177Updated last year
- Check VM/SandBox☆15Updated last year
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆33Updated 6 months ago
- Next Generation C2 Framework☆113Updated this week