brosck / L1LKiller
「⚠️」Performing a BYOVD on the truesight.sys driver
☆30Updated 2 months ago
Alternatives and similar repositories for L1LKiller:
Users that are interested in L1LKiller are comparing it to the libraries listed below
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated last year
- ☆52Updated 3 months ago
- Make an Linux Kernel rootkit visible again.☆47Updated last month
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆30Updated 2 months ago
- A havoc UI python module to help in reporting and vulnerabilities to exploit on an internal network.☆12Updated last year
- PowerShell script to generate ShellCode in various formats☆41Updated 4 months ago
- Brief writeup of post exploitation methodologies.☆17Updated last year
- Windows Thread Pool Injection Havoc Implementation☆28Updated 10 months ago
- Situational Awareness script to identify how and where to run implants☆45Updated 2 months ago
- Inject RDPThief into memory with PowerShell.☆59Updated 3 weeks ago
- POC for CVE-2024-3183 (FreeIPA Rosting)☆18Updated 5 months ago
- A command and control framework.☆43Updated last month
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆39Updated 8 months ago
- Construct the payload at runtime using an array of offsets☆61Updated 7 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- ☆54Updated 3 months ago
- Section-based payload obfuscation technique for x64☆59Updated 6 months ago
- UAC Bypass using CMSTP in Rust☆23Updated 2 months ago
- this script adds the ability to encode shellcode (.bin) in XOR,chacha20, AES. You can choose between 2 loaders (Myph / 221b)☆78Updated last year
- Bypass the Event Trace Windows(ETW) and unhook ntdll.☆102Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 6 months ago
- in-process powershell runner for BRC4☆44Updated last year
- This is way to load a shellcode, and obfuscate it, so it avoids scantime detection.☆55Updated 7 months ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 2 months ago
- A repository with my code snippets for research/education purposes.☆49Updated last year
- A pure C version of SymProcAddress☆25Updated 10 months ago
- RDE1 (Rusty Data Exfiltrator) is client and server tool allowing auditor to extract files from DNS and HTTPS protocols written in Rust. �…☆39Updated last year
- .bin file to shellcode convertor☆32Updated 7 months ago
- C++ Staged Shellcode Loader with Evasion capabilities.☆79Updated 4 months ago
- ☆13Updated last month