RITRedteam / nosferatuLinks
Windows NTLM Authentication Backdoor
☆18Updated 3 years ago
Alternatives and similar repositories for nosferatu
Users that are interested in nosferatu are comparing it to the libraries listed below
Sorting:
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 3 years ago
- Small tool to play with IOCs caused by Imageload events☆42Updated 2 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 3 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆30Updated 3 years ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆56Updated 2 years ago
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.☆62Updated 3 years ago
- An example of COM hijacking using a proxy DLL.☆28Updated 3 years ago
- Enabled / Disable LSA Protection via BYOVD☆71Updated 3 years ago
- Grab Firefox post requests by hooking PR_Write function from nss3.dll module using trampoline hook to get passwords and emails of users☆42Updated 2 years ago
- API Hammering with C++20☆49Updated 2 years ago
- using the gpu to hide your payload☆59Updated 2 years ago
- ☆39Updated 4 years ago
- Process Injection: APC Injection☆33Updated 4 years ago
- ☆37Updated 2 years ago
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Free☆62Updated 2 years ago
- A simple Linux in-memory .so loader☆30Updated 2 years ago
- Artemis - C++ Hell's Gate Syscall Implementation☆33Updated last year
- Unpacker for donut shellcode☆17Updated 5 years ago
- ☆39Updated 2 years ago
- Bypass UAC on Windows 10/11 x64 using ms-settings DelegateExecute registry key.☆77Updated 2 years ago
- Piece of code to detect and remove hooks in IAT☆64Updated 3 years ago
- A Bumblebee-inspired Crypter☆79Updated 2 years ago
- Non organized Cpp code files I used for my research on Windows☆25Updated 4 years ago
- Recreating and reviewing the Windows persistence methods☆38Updated 3 years ago
- ☆82Updated 10 months ago
- C code to enable ETW tracing for Dotnet Assemblies☆31Updated 2 years ago
- Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/☆37Updated 3 years ago
- (Sim)ulate (Ba)zar Loader☆29Updated 4 years ago
- A Poc on blocking Procmon from monitoring network events☆103Updated 2 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆38Updated 2 years ago