a0rtega / metame
metame is a metamorphic code engine for arbitrary executables
☆569Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for metame
- Demos of various injection techniques found in malware☆792Updated 2 years ago
- A memory scanning evasion technique☆836Updated 7 years ago
- PowerLoaderEx - Advanced Code Injection Technique for x32 / x64☆359Updated 7 years ago
- This is a **WIP** tool that performs shellcode obfuscation in x86 instruction set.☆228Updated 8 years ago
- An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.☆494Updated 5 years ago
- My implementation of enSilo's Process Doppelganging (PE injection technique)☆580Updated 2 years ago
- A set of tutorials about code injection for Windows.☆305Updated 2 months ago
- A tool to detect and crash Cuckoo Sandbox☆288Updated 3 months ago
- ☆798Updated 4 years ago
- Search for code cave in all binaries☆276Updated 4 months ago
- Mirror of users section of rootkit.com☆289Updated 8 years ago
- makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]☆732Updated 5 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆352Updated 4 years ago
- Kernel rootkit, that lives inside the Windows registry values data☆488Updated 7 years ago
- ☆393Updated 7 years ago
- ☆518Updated 6 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆581Updated 7 years ago
- Portable Executable parsing library (from PE-bear)☆648Updated 2 months ago
- C++ application that uses memory and code hooks to detect packers☆268Updated 6 years ago
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆360Updated 4 years ago
- A shellcode writing toolkit☆660Updated 2 years ago
- Shellcode Compiler☆1,065Updated 2 months ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆792Updated 2 years ago
- Obfuscate specific windows apis with different apis☆982Updated 3 years ago
- InjectProc - Process Injection Techniques [This project is not maintained anymore]☆994Updated 5 years ago
- A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)☆389Updated 6 months ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆310Updated 7 months ago
- InfectPE - Inject custom code into PE file [This project is not maintained anymore]☆321Updated 7 years ago
- zer0m0n driver for cuckoo sandbox☆355Updated 9 years ago