aaaddress1 / winInject101
Windows Injection 101: from Zero to ROP (HITCON 2017)
☆28Updated 7 years ago
Alternatives and similar repositories for winInject101:
Users that are interested in winInject101 are comparing it to the libraries listed below
- ☆22Updated 4 years ago
- Example for PagedOut!☆24Updated 5 years ago
- ☆31Updated 4 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆38Updated 4 years ago
- Windows GPU rootkit PoC by Team Jellyfish☆35Updated 9 years ago
- Kernel mode windows NT API logger☆22Updated 5 years ago
- Resources from my journey into Windows binary exploitation☆22Updated 6 years ago
- Execute an arbitrary command within the context of another process☆19Updated 5 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 5 months ago
- Windows Application Loader Running *.Exe files in Memory against Scrylla☆21Updated 5 years ago
- ☆13Updated 7 years ago
- A new binary injection technique, can easily go through any #CIG protected process and slip through all possible defenses without any inj…☆17Updated 6 years ago
- ☆11Updated 5 years ago
- Call 32bit NtDLL API directly from WoW64 Layer☆60Updated 4 years ago
- Create a C++ PE which loads an XTEA-crypted .NET PE shellcode in memory.☆16Updated 6 years ago
- ☆24Updated 3 years ago
- Remote PE reflective injection with a simple reflective loader☆31Updated 5 years ago
- Yet another Windows DLL injector.☆38Updated 3 years ago
- ☆11Updated 2 years ago
- Non organized Cpp code files I used for my research on Windows☆18Updated 4 years ago
- An example of PE hollowing injection technique☆22Updated 5 years ago
- ☆12Updated 4 years ago
- Self-Loading Registration Free COM Functions☆11Updated 5 years ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 6 years ago
- The project was upgraded from https://coder.pub/ and supported VS2017. The original author wrote the detailed design ideas documentation…☆19Updated 7 years ago
- exploit termdd.sys(support kb4499175)☆58Updated 5 years ago
- ☆16Updated 3 years ago
- ☆45Updated 4 years ago
- Win32k Elevation of Privilege PocUpdated 5 years ago