crisprss / Extracted_WD_VDMLinks
Windows Defender VDM lua collections
☆47Updated 2 years ago
Alternatives and similar repositories for Extracted_WD_VDM
Users that are interested in Extracted_WD_VDM are comparing it to the libraries listed below
Sorting:
- Beacon compiled using clang☆71Updated 2 years ago
- An implementation of an indirect system call☆129Updated last year
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆35Updated 2 years ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆56Updated last month
- ☆15Updated 3 years ago
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆33Updated 3 weeks ago
- ☆91Updated 4 years ago
- UAC_wenpon☆49Updated 3 years ago
- Hide Port In Windows☆40Updated 9 months ago
- ☆81Updated 3 years ago
- ☆32Updated 5 years ago
- defender_database☆22Updated last year
- ☆37Updated 5 years ago
- Coffee is a loader for ELF (Executable and Linkable Format) object files written in Rust. Coffee是一个用Rust语言编写的ELF object文件的加载器☆62Updated last year
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆60Updated 4 years ago
- 简单安排一下 autochk.sys 这个rootkit☆72Updated 2 years ago
- ☆22Updated 4 years ago
- use aswArPot.sys to kill process☆68Updated 2 years ago
- shellcode生成框架☆88Updated last year
- ☆40Updated 3 years ago
- frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can …☆52Updated 2 years ago
- bypass UAC even when configured to always notify user☆30Updated 3 years ago
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆138Updated 9 months ago
- DLL Unhooking☆12Updated 4 years ago
- Client/server code that impersonates TLS 1.3 to disguise C2 activity.☆70Updated 3 years ago
- 针对于AzureAttestService服务的本地提权Eop,微软表示已经进行修复☆2Updated 3 years ago
- ☆15Updated 2 years ago
- ☆41Updated last year
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆53Updated last year
- vehsyscall:a syscall project that may bypass EDR☆58Updated last year