Process doppelganging POC using direct system calls, PPID spoofing and dropbox as an external delivery channel for the payload.
☆18Jan 7, 2021Updated 5 years ago
Alternatives and similar repositories for ProcessDoppelganging
Users that are interested in ProcessDoppelganging are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- works but not work, cao!☆24Sep 4, 2021Updated 4 years ago
- Loads shellcode from a resource file.☆21Aug 15, 2019Updated 6 years ago
- Modify data structures in the Windows kernel, hiding processes by PID☆16Oct 29, 2017Updated 8 years ago
- Released presentations of my talks + code that used during these talks☆15Sep 5, 2024Updated last year
- Create a C++ PE which loads an XTEA-crypted .NET PE shellcode in memory.☆17Sep 29, 2018Updated 7 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- TLS Examples in Schannel and IO Completion Ports☆12Jun 21, 2022Updated 4 years ago
- Injects shellcode into remote processes using direct syscalls☆77Dec 30, 2020Updated 5 years ago
- Windows PE Signature Thief in C++☆51Aug 21, 2020Updated 5 years ago
- Modern C++ wrapper for Windows PE signature verification mechanism☆30Aug 9, 2019Updated 7 years ago
- BlowBeef is a tool for analyzing WMI data.☆18Jul 26, 2021Updated 5 years ago
- Monitor ETW events for Windows process mitigation policies, with stack traces☆30Oct 7, 2022Updated 3 years ago
- A PE32/PE32+ parser written in MASM32☆13Feb 24, 2016Updated 10 years ago
- Bypass AMSI and Executing PowerShell scripts from C# - using CyberArk's method to bypass AMSI☆29Feb 22, 2020Updated 6 years ago
- Added working RDP☆12Jan 17, 2017Updated 9 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- This is a random process injector, and more injection techniques will be added in the future.☆13Jul 17, 2020Updated 6 years ago
- Enumerate the DLLs/Modules using NtQueryVirtualMemory☆32Jun 11, 2015Updated 11 years ago
- Alternative Mimikatz LSASS DUMPER☆14Apr 2, 2020Updated 6 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆78Feb 27, 2020Updated 6 years ago
- 无模块注入工程 VS2008☆11Jul 23, 2018Updated 8 years ago
- Add export function and convert exe to dll☆27Sep 20, 2020Updated 5 years ago
- NMAP script to enumerate users via finger☆15Jul 25, 2013Updated 13 years ago
- Tool to get NT system shell .☆24Jul 12, 2021Updated 5 years ago
- WoW64 -> x64☆18Oct 1, 2016Updated 9 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- VisualStudio port of https://github.com/guervild/BOFs/tree/dev/SilentLsassDump☆23Jul 6, 2023Updated 3 years ago
- Modified Version of Melkor @FuzzySecurity capable of creating disposable AppDomains in injected processes.☆28Sep 8, 2021Updated 4 years ago
- C++ implementation of DOUBLEPULSAR usermode shellcode. Yet another Reflective DLL loader.☆30Nov 9, 2021Updated 4 years ago
- Terminate the eventlog thread to disable the windows eventlog☆21Apr 1, 2020Updated 6 years ago
- A collection of scripts used to support an OffSecOps pipeline.☆15Jan 31, 2021Updated 5 years ago
- ☆32Jul 2, 2020Updated 6 years ago
- posting example☆15May 11, 2020Updated 6 years ago
- Cobalt Strike teamserver detection.☆16Apr 26, 2021Updated 5 years ago
- Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly☆118Sep 30, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Playing with packets in C#☆15Aug 16, 2024Updated last year
- MiniDumpWriteDump behavior modification hook☆50Feb 15, 2021Updated 5 years ago
- An Ansible role to install cobalt-strike☆16Aug 24, 2020Updated 5 years ago
- [POC Detected]Bypass BE Anti Dll Injection (POC/Need Driver)☆18Mar 30, 2020Updated 6 years ago
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆107Jan 3, 2021Updated 5 years ago
- 与反病毒软件老大哥们的打闹日常☆14Nov 8, 2018Updated 7 years ago
- ☆18Sep 10, 2021Updated 4 years ago