deepinstinct / ShimMe
☆136Updated 3 months ago
Alternatives and similar repositories for ShimMe:
Users that are interested in ShimMe are comparing it to the libraries listed below
- Port of Cobalt Strike's Process Inject Kit☆162Updated last month
- Construct the payload at runtime using an array of offsets☆61Updated 7 months ago
- ☆137Updated last month
- ☆122Updated 4 months ago
- ☆120Updated last year
- ☆60Updated 8 months ago
- TypeLib persistence technique☆103Updated 3 months ago
- Create Anti-Copy DRM Malware☆51Updated 5 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- Sleep obfuscation☆206Updated last month
- Bypass LSA protection using the BYODLL technique☆154Updated 4 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, f…☆152Updated 8 months ago
- Do some DLL SideLoading magic☆77Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆169Updated 2 months ago
- Just another C2 Redirector using CloudFlare.☆84Updated 8 months ago
- Stage 0☆148Updated last month
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated last year
- Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.☆114Updated 3 months ago
- BOF with Synthetic Stackframe☆103Updated this week
- Generic PE loader for fast prototyping evasion techniques☆191Updated 6 months ago
- ApexLdr is a DLL Payload Loader written in C☆106Updated 6 months ago
- "Service-less" driver loading☆150Updated 2 months ago
- A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.☆66Updated 2 months ago
- ☆87Updated 2 weeks ago
- Shellcode loader☆75Updated 2 months ago
- ☆146Updated last year
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆125Updated 5 months ago
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆149Updated last year