ZephrFish / HelloJackHunterLinks
Research into WinSxS binaries and finding hijackable paths
☆30Updated 2 months ago
Alternatives and similar repositories for HelloJackHunter
Users that are interested in HelloJackHunter are comparing it to the libraries listed below
Sorting:
- ☆109Updated 11 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆84Updated last year
- ☆53Updated 4 months ago
- ☆100Updated last year
- Threadless shellcode injection tool☆68Updated last year
- ☆92Updated last year
- Tool to bypass LSA Protection (aka Protected Process Light)☆64Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated 2 years ago
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆88Updated 11 months ago
- ☆83Updated last year
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆85Updated 2 years ago
- Bypassing Amsi using LdrLoadDll☆47Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated 2 years ago
- ☆122Updated 2 years ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆66Updated 11 months ago
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆66Updated 2 years ago
- ☆126Updated last year
- ☆100Updated 2 years ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆42Updated 2 years ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Updated last month
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Updated last year
- Lateral movement with DCOM DLL hijacking☆176Updated 7 months ago
- remote process injections using pool party techniques☆70Updated 7 months ago
- A BOF to enumerate system process, their protection levels, and more.☆124Updated last year
- Basic interactive Windows kernel offensive toolkit written in C☆135Updated 4 months ago
- Create Anti-Copy DRM Malware☆71Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61Updated 8 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆105Updated 2 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆88Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆86Updated 2 years ago