cod3nym / Ghosting-AMSILinks
Ghosting-AMSI
☆18Updated 8 months ago
Alternatives and similar repositories for Ghosting-AMSI
Users that are interested in Ghosting-AMSI are comparing it to the libraries listed below
Sorting:
- Folder Or File Delete to Get System Shell on Current Session Desktop☆47Updated 11 months ago
- Linux Sleep Obfuscation☆108Updated last year
- ☆77Updated last year
- Bypasses AMSI protection through remote memory patching and parsing technique.☆54Updated 7 months ago
- Commandline spoofing on Windows☆83Updated last month
- A more reliable way of resolving syscall numbers in Windows☆52Updated last year
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- various methods of making API calls☆19Updated 10 months ago
- ☆80Updated last year
- From C to binary shellcode converter.☆48Updated last month
- From C, Rust or Zig to binary shellcode compiler based on Mingw gcc. It allows using Win32 APIs and standard libraries without any change…☆52Updated 3 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆41Updated 2 years ago
- ☆59Updated 8 months ago
- ☆31Updated last year
- A synergized Visual Studio and Rust development environment☆19Updated 11 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆88Updated last year
- ☆32Updated last year
- ☆108Updated last year
- ☆38Updated 8 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆74Updated 11 months ago
- ☆98Updated last year
- An In-memory Embedding of CPython☆31Updated 4 years ago
- ☆59Updated last year
- use python on windows with full submodule support without installation☆30Updated 11 months ago
- Things i do because i saw it on twitter on a weekend☆57Updated 5 months ago
- A bunch of shenanigans using functions, VEH and more☆37Updated 6 months ago
- Demoting PPL anti-malware services to less than a guest user☆66Updated 11 months ago
- macOS dylib stager☆36Updated 11 months ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆50Updated 11 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆42Updated 8 months ago