SafeBreach-Labs / MagicDot
A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue
☆98Updated last year
Alternatives and similar repositories for MagicDot:
Users that are interested in MagicDot are comparing it to the libraries listed below
- ☆72Updated 8 months ago
- A more reliable way of resolving syscall numbers in Windows☆49Updated last year
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 3 months ago
- ☆30Updated 4 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆92Updated this week
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated 8 months ago
- Just another ntdll unhooking using Parun's Fart technique☆74Updated 2 years ago
- Find DLLs with RWX section☆79Updated last year
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- ☆110Updated 5 months ago
- Select any exported function in a dll as the new dll's entry point.☆77Updated 6 months ago
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆18Updated 11 months ago
- ☆28Updated 11 months ago
- ☆98Updated last year
- Tool for playing with Windows Access Token manipulation.☆54Updated 2 years ago
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- ☆55Updated 3 months ago
- shell code example☆46Updated last week
- I have documented all of the AMSI patches that I learned till now☆71Updated 3 weeks ago
- Local & remote Windows DLL Proxying☆164Updated 10 months ago
- ☆154Updated 4 months ago
- ☆103Updated 3 months ago
- ☆61Updated 10 months ago
- ☆105Updated 5 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- ☆105Updated 9 months ago
- ForsHops☆41Updated last month
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- "Service-less" driver loading☆151Updated 4 months ago