VollRagm / apphost-extract
Extracts the files embedded inside of a .NET AppHost.
☆18Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for apphost-extract
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆46Updated last year
- VMP Mutation API Fix☆39Updated 2 years ago
- ntoskrnl .data hooks for UM-KM communication☆34Updated 5 months ago
- Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.☆24Updated 5 years ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆30Updated 7 months ago
- A Proof-of-Concept implementation for Proxy Object Obfuscation in .NET☆45Updated last year
- Bypasses for Windows kernel callbacks PatchGuard protection☆42Updated 3 years ago
- JITK - JIT Killer is hooker for clrjit☆29Updated last year
- Dump .net assembly from a native loader which uses ClrCreateinstance☆53Updated 2 years ago
- Bypassing kernel patch protection runtime☆19Updated last year
- PoC kernel to usermode injection☆59Updated 8 months ago
- PAGE_GUARD based hooking library☆40Updated 2 years ago
- ☆34Updated 4 months ago
- Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide☆18Updated last year
- A simple tool to assemble shellcode ready to be copy-pasted into code☆64Updated 2 years ago
- Obfuscate calls to imports by patching in stubs☆64Updated 3 years ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆40Updated last year
- VM for crackmes, just for fun☆11Updated last year
- Decrypt VMProtect (.NET) obfuscated strings. Made by Cabbo with love.☆24Updated last year
- This is an EfiGuard BootLoader that can boot EfiGuard from Usermode with no USB or Setup as a Single Executable with automatic File Dumpi…☆30Updated 2 months ago
- Utility that tries to generate every single CIL opcode possible in a valid context.☆26Updated 2 years ago
- Compileable POC of namazso's x64 return address spoofer.☆47Updated 4 years ago
- Allows for same-file KernelMode function execution using Encrypted addresses of Functions☆23Updated last month
- Kernel ReClassEx☆63Updated last year
- Makes IDA (most versions) to crash upon opening it.☆64Updated 2 months ago
- DSE & PG bypass via BYOVD attack☆37Updated 7 months ago