OtterHacker / HookerLinks
☆108Updated 10 months ago
Alternatives and similar repositories for Hooker
Users that are interested in Hooker are comparing it to the libraries listed below
Sorting:
- .NET tool used to enrich RPC telemetry☆99Updated 3 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Updated last year
- Impersonate Tokens using only NTAPI functions☆80Updated 5 months ago
- ☆157Updated 9 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆52Updated last year
- ☆147Updated 10 months ago
- "Service-less" driver loading☆161Updated 9 months ago
- A Payload Analysis Framework☆85Updated 2 months ago
- Find DLLs with RWX section☆81Updated 2 years ago
- A Mythic Agent written in PIC C.☆199Updated 7 months ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆103Updated 5 months ago
- Blog/Journal on how to backdoor VSCode extensions☆73Updated last month
- Modern PIC implant for Windows (64 & 32 bit)☆103Updated last month
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆120Updated last year
- Remote DLL Injection with Timer-based Shellcode Execution☆96Updated last month
- A collection of position independent coding resources☆93Updated this week
- Section-based payload obfuscation technique for x64☆64Updated last year
- ☆112Updated 9 months ago
- EvtPsst☆55Updated last year
- ☆76Updated last year
- ☆135Updated 7 months ago
- Bypasses AMSI protection through remote memory patching and parsing technique.☆50Updated 4 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆47Updated last year
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆98Updated last year
- Bypass user-land hooks by syscall tampering via the Trap Flag☆114Updated 3 weeks ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆89Updated last year
- A small How-To on creating your own weaponized WSL file☆115Updated last month
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆140Updated last year