cbrnrd / maliketh
🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python
☆42Updated 10 months ago
Alternatives and similar repositories for maliketh:
Users that are interested in maliketh are comparing it to the libraries listed below
- a demo module for the kaine agent to execute and inject assembly modules☆38Updated 4 months ago
- stack spoofing☆74Updated 2 months ago
- Classic Process Injection with Memory Evasion Techniques implemantation☆66Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆46Updated 4 months ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated 11 months ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆43Updated 10 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- ☆19Updated 5 months ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆65Updated last month
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆40Updated 6 months ago
- A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user☆36Updated 5 months ago
- DLL Hijacking and Mock directories technique to bypass Windows UAC security feature and getting high-level privileged reverse shell. Secu…☆37Updated 8 months ago
- ☆35Updated last year
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆36Updated last year
- Exploiting the KsecDD Windows driver through Server Silos☆37Updated 2 months ago
- (EDR) Dll Unhooking = kernel32.dll, kernelbase.dll, ntdll.dll, user32.dll, apphelp.dll, msvcrt.dll.☆18Updated 5 months ago
- Threadless injection via TLS callbacks☆16Updated last month
- BOF with Synthetic Stackframe☆58Updated this week
- API Hammering with C++20☆42Updated 2 years ago
- using the gpu to hide your payload☆53Updated 2 years ago
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆55Updated last year
- Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules☆42Updated last year
- Mockingjay Process Injection Vulnerable DLL Finder☆18Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆60Updated last year
- Various methods of executing shellcode☆70Updated last year
- ☆36Updated last year
- An initial proof of concept of a bootkit based on Cr4sh's DMABackdoorBoot☆61Updated last year
- A proof of concept I developed to improve Gargoyle back in 2018 to achieve true memory obfuscation from position independent code☆40Updated 4 months ago