dosxuz / PerunsFart
This is my own implementation of the Perun's Fart technique by Sektor7
☆67Updated 2 years ago
Alternatives and similar repositories for PerunsFart:
Users that are interested in PerunsFart are comparing it to the libraries listed below
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆96Updated last year
- ☆39Updated 2 years ago
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆78Updated 2 years ago
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆38Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆82Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- ☆46Updated 2 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆52Updated last year
- EmbedExeLnk by x86matthew modified by d4rkiZ☆30Updated last year
- ☆61Updated 2 years ago
- ☆96Updated last year
- Repo that holds random POCs☆48Updated last year
- A simple BOF that frees UDRLs☆114Updated 2 years ago
- ☆73Updated last year
- Beacon Object Files (not Buffer Overflows)☆53Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆90Updated 11 months ago
- ☆35Updated last year
- DLL Exports Extraction BOF with optional NTFS transactions.☆80Updated 3 years ago
- ☆42Updated last year
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆84Updated 2 years ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆77Updated 3 months ago
- Sleep Obfuscation☆42Updated 2 years ago
- Quick python script to replace the NtAPI functions within SysWhispers' assembly and header files with random strings☆25Updated 2 years ago
- ☆126Updated last year
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆60Updated 10 months ago