cocomelonc / offzone-2024-malware-persistence-workshop
OFFZONE 2024 Malware Persistence workshop
☆19Updated 4 months ago
Alternatives and similar repositories for offzone-2024-malware-persistence-workshop
Users that are interested in offzone-2024-malware-persistence-workshop are comparing it to the libraries listed below
Sorting:
- Windows AppLocker Driver (appid.sys) LPE☆56Updated 9 months ago
- POC of GITHUB simple C2 in rust☆53Updated 3 months ago
- Unhook Ntdll.dll, Go & C++.☆22Updated 3 weeks ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆81Updated this week
- Red Team Operation's Defense Evasion Technique.☆52Updated 11 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆48Updated last year
- Ghosting-AMSI☆17Updated 2 weeks ago
- ☆46Updated last month
- NailaoLoader: Hiding Execution Flow via Patching☆20Updated 2 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- ☆34Updated last month
- Section-based payload obfuscation technique for x64☆59Updated 9 months ago
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆42Updated 10 months ago
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 5 years ago
- using the gpu to hide your payload☆57Updated 2 years ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 4 months ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆21Updated 6 months ago
- ☆55Updated 6 months ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆57Updated last year
- Mockingjay process self injection POC☆32Updated last year
- ☆48Updated last year
- Create Anti-Copy DRM Malware☆56Updated 8 months ago
- Folder Or File Delete to Get System Shell on Current Session Desktop☆39Updated 4 months ago
- ☆61Updated 11 months ago
- Malware?☆70Updated 7 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 10 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆24Updated last month
- ☆58Updated 3 months ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆49Updated 3 months ago
- Golang bindings for PE-sieve☆43Updated last year