cocomelonc / offzone-2024-malware-persistence-workshop
OFFZONE 2024 Malware Persistence workshop
☆15Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for offzone-2024-malware-persistence-workshop
- Mythic C2 Agent written in x64 PIC C☆26Updated this week
- Golang bindings for PE-sieve☆40Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆36Updated 3 months ago
- Red Team Operation's Defense Evasion Technique.☆52Updated 5 months ago
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆25Updated 3 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆61Updated last month
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆22Updated 2 months ago
- A simple commandline application to automatically decrypt strings from Obfuscator protected binaries☆38Updated 5 months ago
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Updated 2 years ago
- EvtPsst☆54Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- Template-based generation of shellcode loaders☆67Updated 7 months ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- ☆18Updated 11 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆37Updated 2 months ago
- Section-based payload obfuscation technique for x64☆58Updated 3 months ago
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 6 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Updated last year
- A Bumblebee-inspired Crypter☆80Updated last year
- miscellaneous codes☆35Updated last year
- ☆33Updated last year
- Collect Windows telemetry for Maldev☆62Updated this week
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆40Updated last year