SafeBreach-Labs / MagicDot
A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue
☆96Updated 10 months ago
Alternatives and similar repositories for MagicDot:
Users that are interested in MagicDot are comparing it to the libraries listed below
- A more reliable way of resolving syscall numbers in Windows☆48Updated last year
- ☆68Updated 6 months ago
- Construct the payload at runtime using an array of offsets☆61Updated 8 months ago
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 10 months ago
- ☆134Updated last year
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆75Updated 6 months ago
- Python module for running BOFs☆68Updated last year
- "Service-less" driver loading☆149Updated 2 months ago
- ☆75Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Find DLLs with RWX section☆76Updated last year
- Slides for COM Hijacking AV/EDR Talk on 38c3☆71Updated last month
- ☆29Updated 2 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- ☆74Updated 9 months ago
- It's pointy and it hurts!☆122Updated 2 years ago
- ☆143Updated 2 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆85Updated last year
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- ☆27Updated 9 months ago
- 32bit MIPS I VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆111Updated 2 months ago
- ☆97Updated last year
- ☆47Updated last year
- ☆107Updated 2 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 7 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- ☆94Updated last month
- ☆103Updated 3 months ago
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆17Updated 9 months ago
- Tool for playing with Windows Access Token manipulation.☆54Updated 2 years ago