coremedic / IndirectProxyCall
Proof of concept demonstrating a method of proxying syscalls indirectly
☆8Updated 6 months ago
Alternatives and similar repositories for IndirectProxyCall:
Users that are interested in IndirectProxyCall are comparing it to the libraries listed below
- ☆88Updated 2 weeks ago
- A collection of position independent coding resources☆64Updated last week
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆41Updated 6 months ago
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆105Updated 4 months ago
- A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.☆66Updated 2 months ago
- Malware?☆69Updated 3 months ago
- A process injection technique using only thread context manipulation☆25Updated last year
- a modified CONTEXT based ropchain to circumvent CFG-FindHiddenShellcode and EtwTi-FluctuationMonitor☆96Updated 10 months ago
- ☆122Updated 4 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- ☆96Updated last year
- ☆83Updated 5 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆172Updated last year
- BOF with Synthetic Stackframe☆103Updated last week
- Patch AMSI and ETW in remote process via direct syscall☆80Updated 2 years ago
- "Service-less" driver loading☆149Updated 2 months ago
- 32bit MIPS I VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆105Updated last month
- AzureAD beacon object files☆108Updated last month
- ☆28Updated 5 months ago
- ☆60Updated 8 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆50Updated 2 months ago
- Find DLLs with RWX section☆76Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆56Updated last year
- Simple BOF to read the protection level of a process☆114Updated last year
- stack spoofing☆77Updated 2 months ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago