cod3nym / Deobfuscar
A simple commandline application to automatically decrypt strings from Obfuscator protected binaries
☆38Updated 7 months ago
Alternatives and similar repositories for Deobfuscar:
Users that are interested in Deobfuscar are comparing it to the libraries listed below
- ☆28Updated 7 months ago
- ☆73Updated last year
- based on https://gitlab.com/ORCA000/snaploader☆42Updated last month
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- A more reliable way of resolving syscall numbers in Windows☆50Updated 11 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- BOF for C2 framework☆40Updated 2 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆76Updated 5 months ago
- ☆83Updated 4 months ago
- ☆96Updated last year
- ☆42Updated last year
- ☆47Updated last year
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 7 months ago
- miscellaneous codes☆35Updated last year
- ☆45Updated 2 months ago
- macOS dylib stager☆26Updated this week
- ☆27Updated 8 months ago
- Create Anti-Copy DRM Malware☆50Updated 4 months ago
- Linux Sleep Obfuscation☆91Updated last year
- Find DLLs with RWX section☆76Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 9 months ago
- Golang bindings for PE-sieve☆41Updated last year
- C++ Staged Shellcode Loader with Evasion capabilities.☆73Updated 3 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year