aaaddress1 / winInject101
Windows Injection 101: from Zero to ROP (HITCON 2017)
☆27Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for winInject101
- ☆22Updated 4 years ago
- ☆31Updated 4 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- Example for PagedOut!☆24Updated 5 years ago
- Kernel mode windows NT API logger☆21Updated 5 years ago
- Resources from my journey into Windows binary exploitation☆22Updated 5 years ago
- A ready-made template for a project based on libpeconv.☆41Updated last month
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆37Updated 3 years ago
- exploit termdd.sys(support kb4499175)☆57Updated 5 years ago
- Remote PE reflective injection with a simple reflective loader☆29Updated 5 years ago
- ☆20Updated 3 years ago
- Yet another Windows DLL injector.☆38Updated 3 years ago
- A new binary injection technique, can easily go through any #CIG protected process and slip through all possible defenses without any inj…☆18Updated 6 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆26Updated 7 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆16Updated last year
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 2 months ago
- Headers for linking your software with ntdll.dll☆15Updated 4 years ago
- Run some secret code invisible from debugger single step.(x86 process on x64 windows only)☆24Updated 4 years ago
- Code Integrity Violation Spotter☆17Updated 5 months ago