ZeroPointSecurity / PInvoke
☆54Updated 2 months ago
Alternatives and similar repositories for PInvoke:
Users that are interested in PInvoke are comparing it to the libraries listed below
- Bypassing Amsi using LdrLoadDll☆43Updated 2 months ago
- Find DLLs with RWX section☆78Updated last year
- ☆38Updated 2 years ago
- ☆127Updated last year
- My implementation of Halo's Gate technique in C#☆54Updated 2 years ago
- Just another ntdll unhooking using Parun's Fart technique☆74Updated 2 years ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆96Updated last year
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆104Updated last year
- ☆109Updated 4 months ago
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆73Updated this week
- ☆53Updated 2 months ago
- ☆35Updated last year
- ☆61Updated 9 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆79Updated 5 months ago
- I have documented all of the AMSI patches that I learned till now☆71Updated last year
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆133Updated 6 months ago
- A collection of (even more) alternative shellcode callback methods in CSharp☆72Updated 5 months ago
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆151Updated last year
- Lateral Movement via the .NET Profiler☆80Updated 4 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- ☆121Updated last year
- ☆98Updated last year
- Shellcode loader using direct syscalls via Hell's Gate and payload encryption.☆90Updated 9 months ago
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆61Updated last year
- A work in progress BOF/COFF loader in Rust☆47Updated 2 years ago
- A C# implementation of dumping credentials from Windows Credential Manager☆56Updated last year
- Create Anti-Copy DRM Malware☆54Updated 7 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Patch AMSI and ETW in remote process via direct syscall☆81Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆83Updated 2 years ago