brosck / L1LKiller
「⚠️」Performing a BYOVD on the truesight.sys driver
☆34Updated 4 months ago
Alternatives and similar repositories for L1LKiller:
Users that are interested in L1LKiller are comparing it to the libraries listed below
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆23Updated last week
- Cortex EDR Ransomware protection Bypass☆21Updated 2 months ago
- Situational Awareness script to identify how and where to run implants☆50Updated 4 months ago
- ☆54Updated 5 months ago
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated last year
- A pure C version of SymProcAddress☆26Updated last year
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆74Updated last month
- Windows Thread Pool Injection Havoc Implementation☆28Updated last year
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆34Updated 4 months ago
- UAC Bypass using CMSTP in Rust☆25Updated 4 months ago
- The Swiss army knife of evasion tool that bypasses AMSI, Applocker, and CLM mode simultaneously.☆27Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆74Updated 8 months ago
- Section-based payload obfuscation technique for x64☆59Updated 8 months ago
- Brief writeup of post exploitation methodologies.☆18Updated last year
- Tool to obtain hash using MS-SNTP for user accounts☆21Updated 2 months ago
- in-process powershell runner for BRC4☆45Updated last year
- ☆37Updated 2 months ago
- Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks☆103Updated 3 months ago
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 4 months ago
- POC for CVE-2024-3183 (FreeIPA Rosting)☆20Updated 8 months ago
- A python script that automates a C2 Profile build☆39Updated 3 weeks ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆28Updated this week
- Enable or Disable TokenPrivilege(s)☆13Updated 11 months ago
- Dumping LSASS Evaded Endpoint Security Solutions☆12Updated 2 months ago
- Impersonate Tokens using only NTAPI functions☆61Updated 2 weeks ago
- Sniffing files generator☆54Updated last month
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆60Updated last year
- Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible i…☆18Updated 2 weeks ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year