OccamsXor / sim-ba
(Sim)ulate (Ba)zar Loader
☆29Updated 4 years ago
Alternatives and similar repositories for sim-ba:
Users that are interested in sim-ba are comparing it to the libraries listed below
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆30Updated 10 months ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago
- I used this to see if an EDR is running in Safe Mode☆34Updated 3 years ago
- Injects shellcode into remote processes using direct syscalls☆74Updated 4 years ago
- A simple dumper as FreshyCalls' PoC. That's what's trendy, isn't it? ¯\_(ツ)_/¯☆39Updated 4 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used