NtRaiseHardError / Sysmon
Sysmon shenanigans
☆66Updated 4 years ago
Alternatives and similar repositories for Sysmon:
Users that are interested in Sysmon are comparing it to the libraries listed below
- ☆69Updated last year
- A tool to create COM class/interface relationships in neo4j☆47Updated 2 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 3 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- ☆36Updated 3 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆47Updated 4 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- A simple COM server which provides a component to run shellcode☆132Updated 4 years ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- ☆31Updated 4 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- Shim database persistence (Fin7 TTP)☆36Updated 4 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆111Updated 3 years ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆45Updated 7 years ago
- A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original…☆93Updated 5 years ago
- Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process☆98Updated last year
- Local OXID Resolver (LCLOR) : Research and Tooling☆34Updated 3 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆100Updated 5 years ago
- DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userla…☆119Updated 2 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆73Updated 4 years ago
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- ☆49Updated 4 years ago
- Windows Drivers☆97Updated 5 years ago
- Windows kernel PDB data parsed into YAML☆34Updated 2 months ago
- A ready-made template for a project based on libpeconv.☆43Updated 2 months ago
- Proxy system calls over an RPC channel☆96Updated 2 years ago