dosxuz / PerunsFart
This is my own implementation of the Perun's Fart technique by Sektor7
☆66Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for PerunsFart
- ☆44Updated 2 years ago
- ☆38Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆51Updated last year
- Beacon Object Files (not Buffer Overflows)☆51Updated last year
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆82Updated 2 years ago
- Sleep Obfuscation☆41Updated 2 years ago
- ☆61Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆38Updated last year
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆39Updated 11 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆85Updated 2 years ago
- DLL Exports Extraction BOF with optional NTFS transactions.☆78Updated 3 years ago
- Repo that holds random POCs☆45Updated 10 months ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes☆94Updated last year
- ☆122Updated 11 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- ☆38Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆88Updated 9 months ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆53Updated 2 years ago
- My implementation of Halo's Gate technique in C#☆53Updated 2 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆92Updated 3 years ago