dr4k0nia / NixImports
A .NET malware loader, using API-Hashing to evade static analysis
☆204Updated last year
Related projects ⓘ
Alternatives and complementary repositories for NixImports
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆165Updated last year
- Patching AmsiOpenSession by forcing an error branching☆144Updated last year
- Generate Shellcode Loaders & Injects☆152Updated last year
- Patch AMSI and ETW☆233Updated 6 months ago
- different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)☆175Updated last year
- .NET assembly loader with patchless AMSI and ETW bypass☆278Updated last year
- Generic PE loader for fast prototyping evasion techniques☆185Updated 4 months ago
- CaveCarver - PE backdooring tool which utilizes and automates code cave technique☆214Updated last year
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆101Updated last year
- Modules used by the Havoc Framework☆204Updated 5 months ago
- Remote Shellcode Injector☆204Updated last year
- (Demo) 3rd party agent for Havoc☆129Updated last year
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆148Updated 10 months ago
- ☆142Updated last year
- Load a dynamic library from memory by modifying the native Windows loader☆204Updated last year
- Create a new thread that will suspend every thread and encrypt its stack, then going to sleep , then decrypt the stacks and resume thread…☆156Updated last year
- Exploitation of process killer drivers☆188Updated last year
- Weaponized HellsGate/SigFlip☆194Updated last year
- ☆63Updated 9 months ago
- C# code to Sandbox Defender (and most probably other AV/EDRs).☆163Updated 2 years ago
- miscellaneous scripts and programs☆215Updated last year
- EDRSandblast-GodFault☆240Updated last year
- Exploitation of echo_driver.sys☆167Updated last year
- Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime☆298Updated last year
- Hide your P/Invoke signatures through other people's signed assemblies☆200Updated 8 months ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆135Updated 6 months ago
- Bypass LSA protection using the BYODLL technique☆150Updated 2 months ago