PacktPublishing / Windows-APT-WarfareLinks
Windows APT Warfare, published by Packt
☆70Updated 2 years ago
Alternatives and similar repositories for Windows-APT-Warfare
Users that are interested in Windows-APT-Warfare are comparing it to the libraries listed below
Sorting:
- ☆119Updated last year
- ☆105Updated 11 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- ☆136Updated 2 years ago
- ☆85Updated 2 years ago
- ☆142Updated 2 years ago
- ☆42Updated 2 years ago
- ☆113Updated 3 years ago
- Finding secrets in kernel and user memory☆116Updated last year
- Small PoC of using a Microsoft signed executable as a lolbin.☆138Updated 2 years ago
- Piece of code to detect and remove hooks in IAT☆64Updated 3 years ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 11 months ago
- Red Team Operation's Defense Evasion Technique.☆53Updated last year
- I have documented all of the AMSI patches that I learned till now☆73Updated 2 months ago
- ETW based POC to identify direct and indirect syscalls☆187Updated 2 years ago
- It's pointy and it hurts!☆126Updated 2 years ago
- ☆107Updated 2 years ago
- Simple BOF to read the protection level of a process☆115Updated 2 years ago
- Malware?☆70Updated 8 months ago
- ☆86Updated last year
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆176Updated 2 years ago
- POC for frustrating/defeating Malware Analysts☆154Updated 3 years ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆123Updated 2 years ago
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆118Updated last year
- Do some DLL SideLoading magic☆84Updated last year
- ☆114Updated 2 years ago
- ☆96Updated 3 years ago
- This project is an implant framework designed for long term persistent access to Windows machines.☆110Updated last year
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆165Updated last year
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆112Updated 9 months ago