ZeroMemoryEx / SleepKiller
Bypass Malware Time Delays
☆101Updated 2 years ago
Alternatives and similar repositories for SleepKiller
Users that are interested in SleepKiller are comparing it to the libraries listed below
Sorting:
- Small PoC of using a Microsoft signed executable as a lolbin.☆137Updated 2 years ago
- It's pointy and it hurts!☆125Updated 2 years ago
- Find DLLs with RWX section☆80Updated last year
- abusing Process Hacker driver to terminate other processes (BYOVD)☆82Updated last year
- A bunch of scripts and code i wrote.☆141Updated 6 months ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆123Updated 2 years ago
- POC for frustrating/defeating Malware Analysts☆154Updated 2 years ago
- Do some DLL SideLoading magic☆84Updated last year
- Splitting and executing shellcode across multiple pages☆102Updated last year
- ☆136Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- ☆115Updated 2 years ago
- A simple PoC to invoke an encrypted shellcode by using an hidden call☆116Updated 2 years ago
- Deleting Shadow Copies In Pure C++☆114Updated 2 years ago
- Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).☆145Updated 2 years ago
- Code used in this post https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html☆123Updated 3 years ago
- Malware?☆70Updated 7 months ago
- This project is an implant framework designed for long term persistent access to Windows machines.☆110Updated last year
- Patch AMSI and ETW in remote process via direct syscall☆81Updated 3 years ago
- Red Team Operation's Defense Evasion Technique.☆52Updated 11 months ago
- Kernel Mode Driver for Elevating Process Privileges☆133Updated 2 years ago
- ☆82Updated 8 months ago
- Experiment on reproducing Obfuscate & Sleep☆144Updated 4 years ago
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆116Updated last year
- Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)☆100Updated last year
- I have documented all of the AMSI patches that I learned till now☆72Updated last month
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆135Updated 2 years ago
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Updated 3 years ago
- A Poc on blocking Procmon from monitoring network events☆101Updated 2 years ago
- A Bumblebee-inspired Crypter☆80Updated 2 years ago