YMahmoudnia / SB-LoaderLinks
SBLoader is a memory patcher to patch and execute the child process under the desired parent process.
☆14Updated 3 years ago
Alternatives and similar repositories for SB-Loader
Users that are interested in SB-Loader are comparing it to the libraries listed below
Sorting:
- A Practical example of ELAM (Early Launch Anti-Malware)☆35Updated 3 years ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆11Updated 2 years ago
- Parser for a custom executable formats from Hidden Bee and Rhadamanthys malware☆55Updated 3 weeks ago
- NT AUTHORITY\SYSTEM☆39Updated 5 years ago
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆37Updated 2 years ago
- Listing UDP connections with remote address without sniffing.☆29Updated last year
- ☆37Updated 6 months ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago
- "An Introduction to Windows Exploit Development" is an open sourced, free Windows exploit development course I created for the Southeast …☆40Updated 5 years ago
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Updated 3 years ago
- ☆74Updated last year
- Overwrite MBR and add own custom message☆16Updated 5 years ago
- ☆28Updated 2 years ago
- PoC for hiding PE exports☆67Updated 4 years ago
- Process Injection without R/W target memory and without creating a remote thread☆19Updated 3 years ago
- C# implementation to produce ROR-13 numeric hash for given function API name☆33Updated 6 years ago
- Neutralize KEPServerEX anti-debugging techniques☆32Updated 2 years ago
- Windows API Hashes used in the malwares☆42Updated 10 years ago
- A C++ Yara Rule Runner☆12Updated 3 years ago
- arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆57Updated 3 years ago
- A simple tool for detecting memory modifications to Windows API.☆23Updated 7 months ago
- Simple API Hooks detector☆72Updated 3 years ago
- ☆64Updated 2 years ago
- Simple PE Packer Which Encrypts .text Section☆50Updated 8 years ago
- VExtension for NTCore Explorer Suite aka CFF Explorer☆41Updated 3 years ago
- ☆22Updated 5 years ago
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆73Updated 4 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆73Updated 2 years ago
- ☆90Updated 4 years ago
- stack based buffer overflow in MsIo64.sys, Proof of Concept Local Privilege Escalation to nt authority/system☆11Updated 4 years ago