Stuuxx / awesome-persistenceLinks
Persistence techniques for windows.
☆19Updated 2 years ago
Alternatives and similar repositories for awesome-persistence
Users that are interested in awesome-persistence are comparing it to the libraries listed below
Sorting:
- A payload delivery system which embeds payloads in an executable's icon file!☆74Updated last year
- Tool for obtaining information about PPL processes☆17Updated last year
- Tartocitron is a repo to have fun with malwares and the Rust language. This repo provides working examples of dropper written in Rust.☆10Updated 3 years ago
- EvtPsst☆55Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 3 years ago
- freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package☆33Updated 2 years ago
- ☆59Updated last year
- Python3 tool to perform password spraying using RDP☆17Updated last year
- Collection of Rust repos useful for Red Teamers.☆34Updated 2 years ago
- API Hammering with C++20☆50Updated 3 years ago
- some AV / EDR / analysis studies☆11Updated 2 years ago
- Extension functionality for the NightHawk operator client☆27Updated last year
- e(X)tensiable (Rust) Malware Toolkit: (Soon!) Full Featured Rust C2 Framework with Awesome Features!☆24Updated 11 months ago
- A utility that can be used to launch an executable with a DLL injected☆20Updated last year
- Just another Process Injection using Process Hollowing technique.☆18Updated last year
- A collection of PoCs for different injection techniques on Windows!☆44Updated last year
- ☆16Updated 3 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆32Updated last year
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆41Updated last year
- Process Ghosting is a technique in which a process is created from a delete pending file. This means the created process is not backed by…☆15Updated last year
- ☆18Updated 7 months ago
- ☆27Updated 3 weeks ago
- This repo for Windows x32-x64 Kernel/Driver/User Mode Exploitation writeups and exploits☆25Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year
- Items related to the RedELK workshop given at security conferences☆29Updated last year
- Docker container for running CobaltStrike 4.10☆37Updated 10 months ago
- ☆59Updated last year
- idk man this was the default github name☆35Updated 2 years ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆57Updated last year
- A pure C version of SymProcAddress☆29Updated last year