dosxuz / TradecraftImrprovementLinks
This repository will contain source codes from the Tradecraft improvement blog series
☆14Updated 10 months ago
Alternatives and similar repositories for TradecraftImrprovement
Users that are interested in TradecraftImrprovement are comparing it to the libraries listed below
Sorting:
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆79Updated 2 years ago
- Rewrite to fit my needs☆32Updated last year
- miscellaneous codes☆36Updated 2 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated last year
- ☆38Updated 9 months ago
- Repository to gather the .NET malware I will be developing☆18Updated 10 months ago
- BasicLDR: A Reflective DLL Loader☆14Updated last year
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆16Updated last year
- One-header configurable C++20 COFF loader☆21Updated 6 months ago
- ☆39Updated 10 months ago
- Section-based payload obfuscation technique for x64☆64Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- BOF for C2 framework☆44Updated last year
- Identifies LOLDrivers that are not blocked by the active HVCI policy — ideal for BYOVD scenarios.☆75Updated 6 months ago
- Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared libra…☆73Updated 2 months ago
- a stage1 DLL loader with sleep obfuscation☆36Updated 3 years ago
- Find jmp gadgets for call stack spoofing.☆76Updated 4 months ago
- ☆61Updated 2 years ago
- Hooked create process injection for meterpreter☆23Updated 4 years ago
- A C# project that builds a Web Application which redirects all HTTPS☆26Updated 11 months ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆51Updated last year
- ☆47Updated 2 years ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆18Updated 7 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆42Updated 9 months ago
- ClickForClickOnce - Generate configurable clickonce payloads☆87Updated 3 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆36Updated last month
- Bunch of BOF files☆38Updated 7 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆52Updated 2 years ago
- ☆47Updated last month
- A pure C version of SymProcAddress☆30Updated last year