dr-anoroc / rawccopy
Command line utility for copying files on NTFS using low level disk access
☆32Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for rawccopy
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- ☆76Updated 2 months ago
- Sysmon shenanigans☆65Updated 4 years ago
- Runs programs as TrustedInstaller☆48Updated 5 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- A simple PoC to demonstrate that is possible to write Non writable memory and execute Non executable memory on Windows☆52Updated 3 years ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆117Updated last year
- An initial proof of concept of a bootkit based on Cr4sh's DMABackdoorBoot☆59Updated last year
- ☆104Updated 2 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆110Updated 3 years ago
- Windows kernel PDB data parsed into YAML☆31Updated last week
- A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original…☆92Updated 5 years ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆48Updated last year
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- code for the Proxy DLL example blog post☆58Updated 3 years ago
- Detours implementation (x64/x86) which used only ntdll import☆88Updated 5 months ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆44Updated 7 years ago
- ☆27Updated 2 years ago
- The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent …☆36Updated 2 years ago
- C# Utilities for Windows Notification Facility☆125Updated 6 months ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆31Updated 2 years ago
- ☆67Updated last year
- ☆65Updated last year
- Files for http://blog.deniable.org/posts/windows-callbacks/☆67Updated 2 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆33Updated 3 years ago
- Windows PDB Parser using Imagehlp library.☆16Updated 2 years ago
- Minifilter Callback Patching Proof-of-Concept☆62Updated 2 years ago
- Finding Truth in the Shadows☆84Updated last year
- ☆36Updated 2 years ago