cocomelonc / offzone-2024-malware-persistence-workshop
OFFZONE 2024 Malware Persistence workshop
☆17Updated last month
Alternatives and similar repositories for offzone-2024-malware-persistence-workshop:
Users that are interested in offzone-2024-malware-persistence-workshop are comparing it to the libraries listed below
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- Unix Process hollowing in rust☆20Updated last month
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 8 months ago
- A few examples of how to trap virtual memory access on Windows.☆18Updated last month
- ☆26Updated 3 months ago
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆44Updated 3 months ago
- API Hammering with C++20☆42Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- havoc kaine plugin to mitigate PAGE_GUARD protected image headers using JOP gadgets☆26Updated 5 months ago
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- A simple commandline application to automatically decrypt strings from Obfuscator protected binaries☆38Updated 7 months ago
- Mythic C2 wrapper for NimSyscallPacker☆22Updated last month
- Threadless injection via TLS callbacks☆16Updated last month
- RunPE adapted for x64 and written in C, does not use RWX☆24Updated 8 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆38Updated 4 months ago
- It's what all the kids are talking about☆12Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- Golang bindings for PE-sieve☆41Updated last year
- based on https://gitlab.com/ORCA000/snaploader☆42Updated last month
- Reimplementation of the KExecDD DSE bypass technique.☆46Updated 4 months ago
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- ☆33Updated 2 years ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆64Updated 2 months ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆19Updated 2 months ago
- Malware AV evasion via disable Windows Defender (Registry). C++☆35Updated 2 years ago
- string encryption in Nim☆17Updated 7 months ago
- BOF for C2 framework☆40Updated 2 months ago