brosck / FrostyLinks
γπ§γRing 3 Rootkit for Windows 10
β60Updated last year
Alternatives and similar repositories for Frosty
Users that are interested in Frosty are comparing it to the libraries listed below
Sorting:
- Kernel Mode Driver for Elevating Process Privilegesβ134Updated 2 years ago
- Windows AppLocker Driver (appid.sys) LPEβ69Updated last year
- β50Updated 3 years ago
- Bypass Malware Sandbox Evasion Ram checkβ142Updated 2 years ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.β65Updated 2 years ago
- γβοΈγRing 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.xβ26Updated 8 months ago
- Various methods of executing shellcodeβ73Updated 2 years ago
- User Mode Windows Rootkitβ67Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process holβ¦β70Updated last year
- abusing Process Hacker driver to terminate other processes (BYOVD)β83Updated 2 years ago
- Rex Shellcode Loader for AV/EDR evasionβ34Updated last year
- XOR decrypting shellcode using the GPU with OpenCL.β117Updated 6 months ago
- Create Anti-Copy DRM Malwareβ70Updated last year
- BYOVD Technique Example using viragt64 driverβ64Updated last year
- Classic Process Injection with Memory Evasion Techniques implemantationβ72Updated 2 years ago
- π‘οΈ A multi-user malleable C2 framework targeting Windows. Written in C++ and Pythonβ45Updated last year
- Splitting and executing shellcode across multiple pagesβ103Updated 2 years ago
- Simple PoC to locate hooked functions by EDR in ntdll.dllβ44Updated 2 years ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.β50Updated last year
- β39Updated 2 years ago
- Identify and exploit leaked handles for local privilege escalation.β111Updated 2 years ago
- Implementation of Indirect Syscall technique to pop a calc.exeβ112Updated last year
- Crossplatform tool for inject shellcode into .exe and .dll binaries (x86 and x64)β74Updated last year
- MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploitβ41Updated 2 years ago
- API Hammering with C++20β49Updated 3 years ago
- β89Updated 2 years ago
- Basic interactive Windows kernel offensive toolkit written in Cβ133Updated 3 months ago
- A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.β111Updated last year
- NativePayload_PE1/PE2 , Injecting Meterpreter Payload bytes into local Process via Delegation Technique + in-memory with delay Changing Rβ¦β59Updated 2 years ago
- Linux Sleep Obfuscationβ106Updated last year