Shrfnt77 / DynamicSyscalls
DynamicSyscalls is a library written in .net resolves the syscalls dynamically (Has nothing to do with hooking/unhooking)
☆63Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for DynamicSyscalls
- Beacon Object Files (not Buffer Overflows)☆51Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- ☆61Updated 2 years ago
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆82Updated 2 years ago
- DLL Exports Extraction BOF with optional NTFS transactions.☆78Updated 3 years ago
- ☆38Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- ☆44Updated 2 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆92Updated 3 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆49Updated 2 years ago
- This is my own implementation of the Perun's Fart technique by Sektor7☆66Updated 2 years ago
- ☆56Updated 3 years ago
- ☆37Updated 10 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- ☆51Updated last year
- Flexible C# shellcode runner☆37Updated 2 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆51Updated last year
- My implementation of Halo's Gate technique in C#☆53Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms☆111Updated last year
- Cobalt Strike BOF for quser.exe implementation using Windows API☆83Updated last year
- A simple BOF that frees UDRLs☆109Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆38Updated last year