cocomelonc / offzone-2024-malware-persistence-workshopLinks
OFFZONE 2024 Malware Persistence workshop
☆19Updated 6 months ago
Alternatives and similar repositories for offzone-2024-malware-persistence-workshop
Users that are interested in offzone-2024-malware-persistence-workshop are comparing it to the libraries listed below
Sorting:
- BSides Prishtina 2024 Malware Development and Persistence workshop☆85Updated last month
- Slides for COM Hijacking AV/EDR Talk on 38c3☆74Updated 6 months ago
- Windows AppLocker Driver (appid.sys) LPE☆62Updated 11 months ago
- A 64 bit executable junk code engine for polymorphic malware.☆48Updated last month
- POC of GITHUB simple C2 in rust☆53Updated 5 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆117Updated last year
- ☆48Updated 3 months ago
- Construct the payload at runtime using an array of offsets☆63Updated last year
- Section-based payload obfuscation technique for x64☆61Updated 11 months ago
- ☆78Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆75Updated 11 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- 「⚠️」Performing a BYOVD on the truesight.sys driver☆38Updated 7 months ago
- CVE-2024-30090 - LPE PoC☆107Updated 8 months ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆22Updated 8 months ago
- Unhook Ntdll.dll, Go & C++.☆25Updated 2 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆50Updated last year
- some leaked src code for known and unknown malwares☆22Updated 3 months ago
- Standalone Metasploit-like XOR encoder for shellcode☆47Updated last year
- A more reliable way of resolving syscall numbers in Windows☆51Updated last year
- Create Anti-Copy DRM Malware☆59Updated 10 months ago
- Red Team Operation's Defense Evasion Technique.☆53Updated last year
- ☆57Updated 2 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆65Updated 3 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- Early cascade injection PoC based on Outflanks blog post written in Rust☆54Updated 5 months ago
- ☆107Updated 8 months ago
- Attacking the cleanup_module function of a kernel module☆36Updated 2 weeks ago
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆86Updated 2 years ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆72Updated last week