deepinstinct / ShimMe
☆136Updated 3 months ago
Alternatives and similar repositories for ShimMe:
Users that are interested in ShimMe are comparing it to the libraries listed below
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 6 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- Sleep obfuscation☆208Updated 2 months ago
- Create Anti-Copy DRM Malware☆52Updated 5 months ago
- Construct the payload at runtime using an array of offsets☆61Updated 7 months ago
- ☆140Updated 2 months ago
- A set of programs for analyzing common vulnerabilities in COM☆189Updated 5 months ago
- ApexLdr is a DLL Payload Loader written in C☆110Updated 6 months ago
- ☆147Updated last year
- Leverage WindowsApp createdump tool to obtain an lsass dump☆145Updated 4 months ago
- ☆122Updated 5 months ago
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆90Updated 11 months ago
- Port of Cobalt Strike's Process Inject Kit☆165Updated 2 months ago
- A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, f…☆155Updated 8 months ago
- TypeLib persistence technique☆106Updated 3 months ago
- Shellcode loader☆77Updated 2 months ago
- Implementing the ghostly hollowing PE injection technique using tampered syscalls.☆131Updated 8 months ago
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆126Updated 6 months ago
- ☆120Updated last year
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆58Updated last year
- Just another C2 Redirector using CloudFlare.☆85Updated 9 months ago
- Windows rootkit designed to work with BYOVD exploits☆157Updated 3 weeks ago
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆116Updated 4 months ago
- ☆138Updated 6 months ago
- BOF with Synthetic Stackframe☆106Updated 3 weeks ago
- ☆60Updated 8 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆172Updated 2 months ago