dr-anoroc / rawccopy
Command line utility for copying files on NTFS using low level disk access
☆34Updated 10 months ago
Alternatives and similar repositories for rawccopy:
Users that are interested in rawccopy are comparing it to the libraries listed below
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- ☆70Updated last year
- Windows kernel PDB data parsed into YAML☆34Updated 3 months ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆32Updated 3 years ago
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 4 years ago
- Portable & Custmizable Windows Defender☆11Updated 3 years ago
- Runs programs as TrustedInstaller☆49Updated 5 years ago
- The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent …☆37Updated 2 years ago
- Small visualizator for PE files☆67Updated last year
- Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping☆51Updated 2 years ago
- ☆80Updated 5 months ago
- Sysmon shenanigans☆65Updated 4 years ago
- ☆25Updated 2 years ago
- ☆109Updated 2 years ago
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆26Updated 2 years ago
- A ready-made template for a project based on libpeconv.☆43Updated 3 months ago
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆65Updated last year
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 9 months ago
- 2022 Updated Kernelmode-Code☆31Updated 10 months ago
- Files for http://blog.deniable.org/posts/windows-callbacks/☆69Updated 2 years ago
- Read Memory without ReadProcessMemory for Current Process☆75Updated 3 years ago
- ☆23Updated last year
- An x64dbg plugin which marks XFG call signatures as data☆73Updated last year
- Remote Thread Detection with a Kernel Driver☆27Updated last month
- Winbindex bot to pull in binaries for specific releases☆45Updated last year
- ☆68Updated 2 weeks ago
- Utility to remove digital code signature from binary PE files in Windows.☆14Updated 3 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- Listing UDP connections with remote address without sniffing.☆30Updated last year
- Yet another Windows DLL injector.☆38Updated 3 years ago