antifob / linux-prinj
Linux process injection PoCs
☆30Updated last year
Alternatives and similar repositories for linux-prinj:
Users that are interested in linux-prinj are comparing it to the libraries listed below
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆98Updated last year
- ☆42Updated 2 years ago
- A more reliable way of resolving syscall numbers in Windows☆49Updated last year
- Shellcode capable of bypassing EAF / IAF mitigations☆12Updated 2 years ago
- Enabled / Disable LSA Protection via BYOVD☆68Updated 3 years ago
- ☆45Updated last month
- Attacking the cleanup_module function of a kernel module☆31Updated last month
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 8 months ago
- API Hammering with C++20☆46Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 4 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 2 months ago
- Piece of code to detect and remove hooks in IAT☆63Updated 2 years ago
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆18Updated 11 months ago
- Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/☆37Updated 3 years ago
- ☆82Updated 8 months ago
- Attack chain emulator. Write recipes for initial access easily☆20Updated 2 months ago
- A few examples of how to trap virtual memory access on Windows.☆30Updated 4 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- ☆30Updated 5 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated 9 months ago
- Splitting and executing shellcode across multiple pages☆101Updated last year
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Free☆62Updated 2 years ago
- ☆61Updated 11 months ago
- A simple PoC to invoke an encrypted shellcode by using an hidden call☆116Updated 2 years ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆62Updated 3 weeks ago
- shell code example☆48Updated 3 weeks ago
- in-process powershell runner for BRC4☆45Updated last year
- MIPS VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆113Updated 5 months ago
- Find DLLs with RWX section☆80Updated last year