anvilsecure / ulexecve
ulexecve is a userland execve() implementation which helps you execute arbitrary ELF binaries on Linux from userland without the binaries ever having to touch storage. This is useful for red-teaming and anti-forensics purposes.
☆185Updated last year
Alternatives and similar repositories for ulexecve:
Users that are interested in ulexecve are comparing it to the libraries listed below
- A stealthy ELF loader - no files, no execve, no RWX☆162Updated last year
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆112Updated last month
- Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86…☆130Updated 2 years ago
- Userland exec PoC to be used as attack vector technique☆85Updated 3 months ago
- Linux Kernel module-less implant (backdoor)☆72Updated 4 years ago
- Elf binary infector written in Go.☆209Updated 3 months ago
- Ghidra scripts for recovering string definitions in Go binaries☆110Updated 5 months ago
- This repo contains write ups of vulnerabilities I've found and exploits I've publicly developed.☆145Updated 2 years ago
- Execute ELF files without dropping them on disk☆491Updated 10 months ago
- stealth userland kit that doesn't use sys_clone/sys_execve call☆30Updated 3 weeks ago
- rp-bf: A library to bruteforce ROP gadgets by emulating a Windows user-mode crash-dump☆115Updated last year
- ☆301Updated last year
- Linpmem is a linux memory acquisition tool☆82Updated 11 months ago
- eBPF hacks☆186Updated 4 months ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆228Updated last year
- bdvl☆113Updated 3 years ago
- ☆203Updated 6 months ago
- Mara is a userland pty/tty sniffer☆53Updated last year
- x86 malware emulator☆217Updated last month
- ☆269Updated 2 years ago
- yxd - Yuu's heX Dumper☆88Updated 10 months ago
- A simple ptrace-less shared library injector for x64 Linux☆258Updated 2 years ago
- A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in c…☆120Updated 2 years ago
- Intercept stdin/stdout/stderr for any process☆198Updated 2 years ago
- ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Sysc…☆117Updated this week
- Exploring RPC interfaces on Windows☆321Updated last year
- A suite of services (SOCKS, FTP, shell, etc.) over Citrix, VMware Horizon and native Windows RDP virtual channels.☆205Updated 3 weeks ago
- Slides & Hands-on for the reverse engineering workshop☆178Updated 2 years ago
- Leveraging CVEs as North Stars in vulnerability discovery and comprehension.☆64Updated last year
- Tools for analyzing EDR agents☆228Updated 10 months ago