ZeroMemoryEx / Overlord
abusing Process Hacker driver to terminate other processes (BYOVD)
☆81Updated last year
Alternatives and similar repositories for Overlord:
Users that are interested in Overlord are comparing it to the libraries listed below
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆101Updated 2 years ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated last year
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆118Updated 2 years ago
- ☆47Updated 2 years ago
- Sleep Obfuscation☆43Updated 2 years ago
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆83Updated 2 years ago
- ☆133Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆62Updated last year
- This is my own implementation of the Perun's Fart technique by Sektor7☆68Updated 2 years ago
- API Hammering with C++20☆45Updated 2 years ago
- bring your own vulnerable driver☆92Updated last year