axcheron / pycaveLinks
Simple tool to find code caves in Portable Executable (PE) files.
☆24Updated 7 years ago
Alternatives and similar repositories for pycave
Users that are interested in pycave are comparing it to the libraries listed below
Sorting:
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆45Updated 4 years ago
- An Xdbg Plugin of the ERC Library.☆26Updated 2 years ago
- PE File Blessing - To continue or not to continue☆87Updated 6 years ago
- Metadata hash incorporating the Rich Header for robustness against packing and other malware tricks☆70Updated 4 years ago
- C++ DLL Bootstrapper for spinning up the CLR for C# Payloads☆44Updated 6 years ago
- Security Descriptor Definition Language (SDDL) Parser☆38Updated 4 months ago
- Dumping credentials through windbg and pykd☆41Updated 2 years ago
- Small visualizator for PE files☆70Updated 2 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 5 years ago
- Bare template for a Kernel Mode Driver☆51Updated 5 years ago
- Process Monitor filter for finding privilege escalation vulnerabilities on Windows☆79Updated 4 years ago
- A simple PoC to demonstrate that is possible to write Non writable memory and execute Non executable memory on Windows☆52Updated 4 years ago
- A git history of Windows filesystems☆77Updated 5 years ago
- Proxy system calls over an RPC channel☆100Updated 4 years ago
- A repository where I share my injection implemintations☆29Updated 5 years ago
- How to set up 2 VirtualBox VM to debug kernel driver using windbg☆57Updated 3 years ago
- Tools that trigger False Positive AV alerts☆53Updated last year
- At some point, I learned about a method to perform a binary search on a file in order to identify its AV signature and change it to bypas…☆36Updated 5 years ago
- Winbindex bot to pull in binaries for specific releases☆48Updated 2 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆100Updated 8 years ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆111Updated 4 years ago
- A tool to create COM class/interface relationships in neo4j☆50Updated 3 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 4 years ago
- A Python script to download PDB files associated with a Portable Executable (PE)☆128Updated 11 months ago
- Raw socket library/framework for red team events☆33Updated 2 years ago
- ☆68Updated 3 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 9 years ago
- From directory deletion to SYSTEM shell☆111Updated 5 years ago
- ☆59Updated 4 years ago
- Malware vulnerability research. Coming soon..☆12Updated 5 years ago