ZeroPointSecurity / PInvoke
☆57Updated 3 months ago
Alternatives and similar repositories for PInvoke:
Users that are interested in PInvoke are comparing it to the libraries listed below
- ☆128Updated last year
- Find DLLs with RWX section☆80Updated last year
- Bypassing Amsi using LdrLoadDll☆44Updated 4 months ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆105Updated 2 years ago
- ☆123Updated last year
- ☆58Updated 3 months ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆97Updated last year
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆75Updated last month
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆180Updated last year
- A C# implementation of dumping credentials from Windows Credential Manager☆57Updated last year
- ☆151Updated last year
- ☆110Updated 5 months ago
- I have documented all of the AMSI patches that I learned till now☆72Updated last month
- ☆39Updated 2 years ago
- Dynamically invoke arbitrary unmanaged code from managed code without P/Invoke.☆159Updated last year
- My implementation of Halo's Gate technique in C#☆54Updated 3 years ago
- Find .net assemblies locally☆113Updated 2 years ago
- A BOF to enumerate system process, their protection levels, and more.☆116Updated 5 months ago
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆151Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- Splitting and executing shellcode across multiple pages☆101Updated last year
- Just another ntdll unhooking using Parun's Fart technique☆75Updated 2 years ago
- C# havoc implant☆99Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆84Updated 2 years ago
- Remotely Enumerate sessions using undocumented Windows Station APIs☆117Updated 8 months ago
- A tool for converting SysWhispers3 syscalls for use with Nim projects☆146Updated 2 years ago
- Terminate AV/EDR leveraging BYOVD attack☆84Updated last month
- C# Port of LdapRelayScan☆83Updated 3 years ago
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆62Updated last year
- Shellcode loader using direct syscalls via Hell's Gate and payload encryption.☆89Updated 10 months ago