crisprss / Extracted_WD_VDMLinks
Windows Defender VDM lua collections
☆47Updated 2 years ago
Alternatives and similar repositories for Extracted_WD_VDM
Users that are interested in Extracted_WD_VDM are comparing it to the libraries listed below
Sorting:
- Beacon compiled using clang☆72Updated 2 years ago
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆35Updated 2 years ago
- An implementation of an indirect system call☆131Updated 2 years ago
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆36Updated 2 months ago
- ☆91Updated 4 years ago
- ☆15Updated 3 years ago
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆57Updated 2 months ago
- UAC_wenpon☆49Updated 3 years ago
- ☆81Updated 3 years ago
- Hide Port In Windows☆40Updated 10 months ago
- use aswArPot.sys to kill process☆68Updated 3 years ago
- ☆37Updated 5 years ago
- ☆40Updated 3 years ago
- frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can …☆55Updated 2 years ago
- ☆32Updated 5 years ago
- ☆22Updated 4 years ago
- 简单安排一下 autochk.sys 这个rootkit☆73Updated 2 years ago
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆138Updated 10 months ago
- ☆42Updated last year
- defender_database☆22Updated last year
- ReturnGate, just like HellsGate.☆68Updated 3 years ago
- ☆50Updated 4 years ago
- Simple windows rpc server for research purposes only☆83Updated 3 years ago
- (Hellsgate|Halosgate|Tartarosgate)+Spoofing-Gate. Ensures that all systemcalls go through ntdll.dll☆44Updated 3 years ago
- Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF☆43Updated 3 years ago
- Client/server code that impersonates TLS 1.3 to disguise C2 activity.☆71Updated 3 years ago
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆60Updated 4 years ago
- 看起来叫BabyBypass,实际啥都会记一些☆16Updated 2 years ago
- Amaterasu terminates, or inhibits, protected processes such as application control and AV/EDR solutions by leveraging the Sysinternals Pr…☆77Updated last year
- ☆21Updated 5 years ago