"D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system calls, randomized procedures, and prototype name obfuscation. Its primary purpose is to bypass both static and dynamic analysis techniques commonly employed by security measures.
☆29Sep 18, 2024Updated last year
Alternatives and similar repositories for D3MPSEC
Users that are interested in D3MPSEC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Direct syscalls Injection to bypass AV/EDR☆10May 18, 2024Updated 2 years ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆31Jan 21, 2024Updated 2 years ago
- This exploit is utilising AddressOfEntryPoint of process which is RX and using WriteProcessMemory internal magic to change the permission…☆20Oct 31, 2024Updated last year
- A tool to assist DLL hijacking via the Havoc GUI☆14Jan 9, 2024Updated 2 years ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆50May 8, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Example of async client/server sockets in .NET 5☆17Jun 9, 2021Updated 5 years ago
- Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-…☆16Jun 4, 2025Updated last year
- A Sublime Text plugin that allows for Nmap syntax highlighting☆13Sep 14, 2024Updated last year
- This exploit use PEB walk technique to resolve API calls dynamically, obfuscate all API calls to perform process injection.☆28Jul 26, 2024Updated 2 years ago
- This comprehensive and central repository is designed for cybersecurity enthusiasts, researchers, and professionals seeking to stay ahead…☆159Jun 10, 2026Updated last month
- Modified versions of the Cobalt Strike Process Injection Kit☆110Jan 24, 2024Updated 2 years ago
- x64 Registration-Free In-Process COM Automation Server.☆50Nov 28, 2022Updated 3 years ago
- string/file/shellcode encryptor using AES/XOR☆11Oct 15, 2023Updated 2 years ago
- Detect userland hooks placed by AV/EDR☆28Sep 4, 2023Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- An improvement and a different approach to Mockingjay Self-Injection.☆35May 21, 2024Updated 2 years ago
- Learning Process Injection and Hollowing techniques☆41Jun 26, 2022Updated 4 years ago
- Explorer Persistence technique : Hijacking cscapi.dll order loading path and writing our malicious dll into C:\Windows\cscapi.dll , when …☆85Jan 12, 2023Updated 3 years ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆80Feb 8, 2023Updated 3 years ago
- Implementation of Indirect Syscall technique to pop a calc.exe☆109Jan 25, 2024Updated 2 years ago
- Bypassing Amsi using LdrLoadDll☆48Jan 8, 2025Updated last year
- A simple Sleepmask BOF example☆178Nov 24, 2025Updated 8 months ago
- This central repository is crafted for cybersecurity enthusiasts, researchers, and professionals aiming to advance their skills. It offer…☆23Jun 10, 2026Updated last month
- .NET assembly loader with patching AMSI and ETW bypass☆33Apr 16, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Simple and sane compression wrapper library.☆19Oct 28, 2022Updated 3 years ago
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 8 months ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆25Oct 30, 2024Updated last year
- Use hardware breakpoint to dynamically change SSN in run-time☆281Apr 10, 2024Updated 2 years ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆50Jul 29, 2024Updated 2 years ago
- ☆27Feb 3, 2026Updated 6 months ago
- Dump Lsass Memory Using a Reflective Dll☆14Feb 4, 2022Updated 4 years ago
- ☆31Jun 1, 2026Updated 2 months ago
- Cobalt Strike BOFS☆17Dec 20, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A collection of PoCs for different injection techniques on Windows!☆53Aug 27, 2023Updated 2 years ago
- Killing any process from low integrity via the BdApiUtil driver from Baidu AV☆26Jun 18, 2025Updated last year
- Collection of Offensive C# Tooling☆13Nov 4, 2021Updated 4 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆40Jul 12, 2024Updated 2 years ago
- Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.☆20Jul 8, 2022Updated 4 years ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆411Jan 11, 2026Updated 6 months ago
- A manual PE mapping implementation, aka reflective loader☆23Feb 28, 2026Updated 5 months ago