ZeroMemoryEx / Overlord
abusing Process Hacker driver to terminate other processes (BYOVD)
☆79Updated last year
Related projects ⓘ
Alternatives and complementary repositories for Overlord
- ☆44Updated 2 years ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated 9 months ago
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆85Updated 2 years ago
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆113Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆49Updated 2 years ago
- Sleep Obfuscation☆41Updated 2 years ago
- ☆35Updated last year
- ☆108Updated last year
- ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption☆78Updated last year
- Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes☆94Updated last year
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆164Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆42Updated 2 months ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated 10 months ago
- ☆73Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- DLL Exports Extraction BOF with optional NTFS transactions.☆78Updated 3 years ago
- ☆61Updated 2 years ago
- This is my own implementation of the Perun's Fart technique by Sektor7☆66Updated 2 years ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- TypeLib persistence technique☆75Updated 3 weeks ago