cocomelonc / offzone-2024-malware-persistence-workshop
OFFZONE 2024 Malware Persistence workshop
☆17Updated 4 months ago
Alternatives and similar repositories for offzone-2024-malware-persistence-workshop:
Users that are interested in offzone-2024-malware-persistence-workshop are comparing it to the libraries listed below
- BSides Prishtina 2024 Malware Development and Persistence workshop☆68Updated this week
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 2 months ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆57Updated last year
- ☆42Updated 3 weeks ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆21Updated 5 months ago
- Windows AppLocker Driver (appid.sys) LPE☆55Updated 8 months ago
- Red Team Operation's Defense Evasion Technique.☆53Updated 10 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 3 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆37Updated last week
- Unhook Ntdll.dll, Go & C++.☆21Updated this week
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆26Updated last year
- IDA Python scripts☆35Updated last week
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 9 months ago
- some leaked src code for known and unknown malwares☆21Updated 3 weeks ago
- ☆27Updated 4 months ago
- A more reliable way of resolving syscall numbers in Windows☆49Updated last year
- ☆29Updated last month
- Repo containing my public talks☆23Updated last year
- A pure C version of SymProcAddress☆26Updated last year
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆54Updated 6 months ago
- NailaoLoader: Hiding Execution Flow via Patching☆20Updated last month
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 5 years ago
- API Hammering with C++20☆46Updated 2 years ago
- A simple commandline application to automatically decrypt strings from Obfuscator protected binaries☆42Updated 10 months ago
- Section-based payload obfuscation technique for x64☆59Updated 8 months ago
- Situational Awareness script to identify how and where to run implants☆50Updated 4 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆48Updated 11 months ago
- POC of GITHUB simple C2 in rust☆53Updated 2 months ago
- Enable or Disable TokenPrivilege(s)☆13Updated 11 months ago