Malware dev tricks. Syscalls part 1. Simple C example
☆10Jun 8, 2023Updated 2 years ago
Alternatives and similar repositories for 2023-06-07-syscalls-1
Users that are interested in 2023-06-07-syscalls-1 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Classic DLL injection. Download dll from url and inject. Simple C++ implementation☆10Apr 16, 2022Updated 3 years ago
- Process injection via KernelCallbackTable☆13Jan 28, 2022Updated 4 years ago
- Malware development: persistence - part 1: startup folder registry keys. C++ implementation☆12Apr 21, 2022Updated 3 years ago
- Malware persistence via COM DLL hijacking. C++ implementation example☆13May 2, 2022Updated 3 years ago
- This repo contains C/C++ snippets that can be handy in specific offensive scenarios.☆12May 31, 2024Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- OFFZONE 2024 Malware Persistence workshop☆22Dec 18, 2024Updated last year
- A simple application to keep on an eye on the availability of HTTP sites☆15Oct 10, 2023Updated 2 years ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆72Feb 11, 2024Updated 2 years ago
- Vulnerabilities exploitation examples, python☆23May 22, 2023Updated 2 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆31Jan 30, 2025Updated last year
- A curated list of tools and techniques written from experience in weaponization of malware☆41Oct 26, 2023Updated 2 years ago
- Find kernel32 base and API addresses. Simple C++ implementation☆23Apr 7, 2022Updated 3 years ago
- POC Tiny PE - Example project showing (almost) minimal executable size. Without touching assembly.☆15Mar 16, 2026Updated last week
- A simple dnSpy extension for easily renaming members.☆20May 27, 2023Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆28Updated this week
- Run payload like a Lazarus Group (UuidFromStringA). C++ implementation☆20Jul 24, 2022Updated 3 years ago
- Windows Research Kernel☆37Sep 22, 2025Updated 6 months ago
- Encrypt/decrypt files and directories using your YubiKey☆16Sep 24, 2023Updated 2 years ago
- 2 PE Loader tools that load a PE from memory, decrypt it and make some magic things to execute seamlessly from memory☆53Nov 7, 2025Updated 4 months ago
- Get windows CPU temperature with WinRing0 driver and library☆25Jan 10, 2019Updated 7 years ago
- Obfuscated Invoke-Mimikatz script☆13May 29, 2018Updated 7 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆11Aug 6, 2018Updated 7 years ago
- Cybersecurity blog. Red Team, pentest, malware analysis and dev☆97Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Windows PDB Parser using Imagehlp library.☆16Sep 16, 2022Updated 3 years ago
- App oficial de Indetectables. Seria un cliente del foro☆23Aug 16, 2021Updated 4 years ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆129Mar 15, 2026Updated 2 weeks ago
- Patch AMSI and ETW in remote process via direct syscall☆85Apr 28, 2022Updated 3 years ago
- A project that uses webgl, written in c++ compiled to wasm with clang.☆14Mar 21, 2022Updated 4 years ago
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Jun 5, 2022Updated 3 years ago
- Mosaique - Remote administration tools☆75Nov 12, 2020Updated 5 years ago
- Bypassing Amsi using LdrLoadDll☆47Jan 8, 2025Updated last year
- Guest to host VM escape exploit for Parallels Desktop☆27Nov 14, 2014Updated 11 years ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A simple tool to assemble shellcode ready to be copy-pasted into code☆71Jun 13, 2022Updated 3 years ago
- Youtube channel sample code☆56Updated this week
- A small Aggressor script to help Red Teams identify foreign processes on a host machine