PacktPublishing / Windows-APT-Warfare
Windows APT Warfare, published by Packt
☆70Updated 2 years ago
Alternatives and similar repositories for Windows-APT-Warfare
Users that are interested in Windows-APT-Warfare are comparing it to the libraries listed below
Sorting:
- ☆113Updated 2 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Simple BOF to read the protection level of a process☆114Updated 2 years ago
- ☆136Updated last year
- Do some DLL SideLoading magic☆83Updated last year
- Finding secrets in kernel and user memory☆115Updated last year
- I have documented all of the AMSI patches that I learned till now☆72Updated last month
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- ☆76Updated 2 years ago
- ☆119Updated last year
- Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms☆127Updated 2 years ago
- Malware?☆70Updated 7 months ago
- Identify and exploit leaked handles for local privilege escalation.☆107Updated last year
- ☆77Updated last year
- Find DLLs with RWX section☆80Updated last year
- Template-based generation of shellcode loaders☆77Updated last year
- Small PoC of using a Microsoft signed executable as a lolbin.☆137Updated 2 years ago
- Lateral Movement via the .NET Profiler☆81Updated 5 months ago
- ☆105Updated 10 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 8 months ago
- A BOF to enumerate system process, their protection levels, and more.☆116Updated 5 months ago
- Implant drop-in for EDR testing☆138Updated last year
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆31Updated 2 years ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆105Updated 2 years ago
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆116Updated last year
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆167Updated last year
- ☆140Updated 2 years ago
- MIPS VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆114Updated 5 months ago
- ☆115Updated 2 years ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆91Updated last year