Overwrite a process's recovery callback and execute with WER
☆104Apr 17, 2022Updated 4 years ago
Alternatives and similar repositories for ARCInject
Users that are interested in ARCInject are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Process Ghosting in C#☆217Jan 24, 2022Updated 4 years ago
- Perun's Fart (Slavic God's Luck). Another method for unhooking AV and EDR, this is my C# version.☆112Dec 26, 2021Updated 4 years ago
- Rewrote HellsGate in C# for fun and learning☆85Feb 10, 2022Updated 4 years ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆375May 24, 2022Updated 4 years ago
- Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique☆337Jan 16, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- You shall pass☆271Jul 16, 2022Updated 4 years ago
- ☆212Apr 5, 2022Updated 4 years ago
- C# version of MDSec's ParallelSyscalls☆143Jan 9, 2022Updated 4 years ago
- RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, …☆498Jan 25, 2022Updated 4 years ago
- Hookers are cooler than patches.☆170Jan 21, 2022Updated 4 years ago
- It stinks☆99Apr 22, 2022Updated 4 years ago
- One gate to all syscalls!☆23Mar 12, 2022Updated 4 years ago
- Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.☆100Mar 27, 2022Updated 4 years ago
- Another meterpreter injection technique using C# that attempts to bypass Defender☆264Oct 20, 2021Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- KaynLdr is a Reflective Loader written in C/ASM☆550Dec 3, 2023Updated 2 years ago
- ☆80Feb 12, 2022Updated 4 years ago
- Nim version of MDSec's Parallel Syscall PoC☆123Apr 4, 2026Updated 5 months ago
- C# Utilities for Windows Notification Facility☆162Apr 14, 2025Updated last year
- An implementation and proof-of-concept of Process Forking.☆230Nov 29, 2021Updated 4 years ago
- some gadgets about windows process and ready to use :)☆615Oct 7, 2023Updated 2 years ago
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆87Jun 24, 2022Updated 4 years ago
- A collection of weird ways to execute unmanaged code in .NET☆171May 4, 2021Updated 5 years ago
- ☆61Feb 10, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- CreateRemoteThreadPlus: how to pass multiple parameters to the remote thread function without shellcode.☆141Jul 10, 2025Updated last year
- FrostByte is a POC project that combines different defense evasion techniques to build better redteam payloads☆382Apr 16, 2022Updated 4 years ago
- How to spoof the command line when spawning a new process from C#.☆111Dec 28, 2021Updated 4 years ago
- Detect strange memory regions and DLLs☆191Jan 20, 2022Updated 4 years ago
- Running .NET from VBA☆147Feb 11, 2023Updated 3 years ago
- Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.☆17Jan 21, 2022Updated 4 years ago
- NativePayload_CallBackTechniques C# Codes (Code Execution via Callback Functions Technique, without CreateThread Native API)☆117Jun 7, 2023Updated 3 years ago
- Various ways to execute shellcode☆512Mar 13, 2024Updated 2 years ago
- UnhookMe is an universal Windows API resolver & unhooker addressing problem of invoking unmonitored system calls from within of your Red …☆347Jul 3, 2022Updated 4 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Beacon Object File PoC implementation of KillDefender☆235Apr 12, 2022Updated 4 years ago
- C# code to Sandbox Defender (and most probably other AV/EDRs).☆164Apr 22, 2022Updated 4 years ago
- Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers t…☆459Oct 25, 2021Updated 4 years ago
- Beacon Object File implementation of Event Viewer deserialization UAC bypass☆132May 6, 2022Updated 4 years ago
- ☆101Mar 31, 2022Updated 4 years ago
- Research project for understanding how Mimikatz work and become better at C☆121Oct 22, 2021Updated 4 years ago
- Hides processes from the windows task manager using IAT hooking.☆22Mar 30, 2021Updated 5 years ago