A cross-platform Python toolkit for parsing/writing PE files.
β67Jun 11, 2024Updated last year
Alternatives and similar repositories for pe_tools
Users that are interested in pe_tools are comparing it to the libraries listed below
Sorting:
- π§Ά The Win32 usermode threading library with UMS/fibers/threads supportβ30Jul 1, 2019Updated 6 years ago
- reducing the entropy of your payloadβ11Aug 15, 2022Updated 3 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLLβ146Feb 23, 2019Updated 7 years ago
- C# code to run PIC using CreateThreadβ17Apr 19, 2019Updated 6 years ago
- Kibana app for RedELKβ18Mar 19, 2023Updated 3 years ago
- SharpDir is a simple code set to search both local and remote file systems for files and is compatible with Cobalt Strike.β30Jul 4, 2019Updated 6 years ago
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxiesβ34Sep 15, 2022Updated 3 years ago
- β23Nov 13, 2021Updated 4 years ago
- β133Dec 4, 2023Updated 2 years ago
- BasicLDR: A Reflective DLL Loaderβ14Jun 11, 2024Updated last year
- Bypass Malware Time Delaysβ107Sep 23, 2022Updated 3 years ago
- Nice try reading NTDLL from disk, nerd.β19Apr 18, 2022Updated 3 years ago
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority threadβ32Sep 24, 2025Updated 5 months ago
- Scripts for public use that we've randomly written, or have updated from other people's work.β40Jun 25, 2024Updated last year
- MSBuild AL bypassβ17Mar 9, 2023Updated 3 years ago
- β18Dec 3, 2025Updated 3 months ago
- C# Situational Awareness Scriptβ34Apr 26, 2019Updated 6 years ago
- Encode binary as English text over HTTP(s)β30Aug 25, 2023Updated 2 years ago
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Freeβ65Mar 8, 2023Updated 3 years ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial β¦β50Jan 25, 2025Updated last year
- Citrix Phishletβ24Feb 2, 2021Updated 5 years ago
- β60Dec 15, 2023Updated 2 years ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machineβ84Jan 6, 2023Updated 3 years ago
- Just another Process Injection using Process Hollowing technique.β18Sep 18, 2023Updated 2 years ago
- Windows file system driver which allows to block access to files at run-time (C/C++, C#, WDK, SDK)β13Jan 1, 2023Updated 3 years ago
- Custom implementation of DbgHelp's MiniDumpWriteDump function. Uses static syscalls to replace low-level functions like NtReadVirtualMemoβ¦β127Jan 18, 2022Updated 4 years ago
- Linux kernel-mode and user-space with wine/MinGW/Windows compability hacking library.β12Sep 15, 2022Updated 3 years ago
- Simple and sane cryptographic wrapper library.β27Apr 21, 2023Updated 2 years ago
- Inline syscalls made for MSVC supporting x64 and WOW64β193Jul 10, 2023Updated 2 years ago
- Fast ssdeep comparison libraryβ13Nov 3, 2014Updated 11 years ago
- β13Jan 12, 2022Updated 4 years ago
- This is the AV ("protection solution") used for my windows 10 rootkit main project. this includes the installer stager program, a serviceβ¦β13May 2, 2024Updated last year
- Serverless Redirector in various cloud vendor for red teamβ73Dec 8, 2022Updated 3 years ago
- Parses Cobalt Strike malleable C2 profiles.β61Updated this week
- A simple program to hook the current process to identify the manual syscall executions on windowsβ266Nov 18, 2022Updated 3 years ago
- COFF and BOF Loader written in Nimβ174Aug 1, 2022Updated 3 years ago
- Modify managed functions from unmanaged codeβ53Feb 1, 2024Updated 2 years ago
- POC tool to convert CobaltStrike BOF files to raw shellcodeβ220Nov 5, 2021Updated 4 years ago
- A Cobaltstrike container, built for Warhorseβ41Aug 8, 2024Updated last year