PPLwindow PPL Bypass via GetProcessHandleFromHwnd
☆54Dec 29, 2025Updated 7 months ago
Alternatives and similar repositories for PPLwindow
Users that are interested in PPLwindow are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A C++/Asm template for PIC/EXE/DLL malware☆24Aug 12, 2025Updated 11 months ago
- ☆19Feb 13, 2026Updated 5 months ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 8 months ago
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 5 months ago
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆141Aug 31, 2025Updated 11 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1☆81Sep 8, 2025Updated 11 months ago
- .data ptr swapper for newer win32k versions. (Supports Windows 11)☆37Jan 19, 2026Updated 6 months ago
- ☆58Jun 10, 2026Updated last month
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆49Mar 3, 2026Updated 5 months ago
- Bring your own Unwind Data Framework☆166Mar 15, 2026Updated 4 months ago
- A tracker DLL which enables 'NTAPI->Syscall' tracking whenever it is loaded. It calls 'NtSetInformationProcess' API call with a callback …☆14Oct 21, 2024Updated last year
- UAC Bypass using UIAccess program QuickAssist☆240Jul 19, 2026Updated 3 weeks ago
- Service Extender for notifying about AdaptixC2 events in Telegram, Slack, Rocket.Char, Discord, and any web platforms, such as ntfy.sh.☆21Mar 4, 2026Updated 5 months ago
- Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared libra…☆88Nov 6, 2025Updated 9 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆69Jul 14, 2026Updated 3 weeks ago
- A newly discovered vulnerable driver, pstrip64.sys (CVE-2026-29923) allows an unprivileged user to escalate privileges to SYSTEM via a cr…☆25Apr 11, 2026Updated 3 months ago
- Educational proof-of-concept demonstrating DEP/NX bypass using hardware breakpoints, vectored exception handling, and instruction emulati…☆102Oct 17, 2025Updated 9 months ago
- Set of PoC to abuse Windows minifilters functionality☆94May 1, 2026Updated 3 months ago
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆234Dec 17, 2025Updated 7 months ago
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆303May 23, 2026Updated 2 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆43Aug 6, 2024Updated 2 years ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated 2 weeks ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆145Apr 22, 2026Updated 3 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Fast covert timing channel communication for inter-process and inter-processor communication on Windows systems.☆73Mar 24, 2026Updated 4 months ago
- Async BOF Framework - Real-time event monitoring for Cobalt Strike Beacon☆30May 18, 2026Updated 2 months ago
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆67Apr 2, 2025Updated last year
- BYOVD: Use 360 WFP driver to block EDR/XDR network connection.☆129Feb 10, 2026Updated 5 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 4 months ago
- A pointer encryption library intended for Red Team implant design in Rust.☆67Oct 1, 2025Updated 10 months ago
- NSecSoftBYOVD POC☆62Feb 12, 2026Updated 5 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 5 months ago
- Obex – Blocking unwanted DLLs in user mode☆281Sep 18, 2025Updated 10 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- A simple POC to show how to chain multiple callbacks via tail calls to artificially construct a call stack☆111May 25, 2026Updated 2 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆106Oct 18, 2025Updated 9 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated 2 weeks ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- ☆14Dec 24, 2023Updated 2 years ago