enkomio / RunDotNetDll
A simple utility to list all methods of a given .NET Assembly and to invoke them
☆73Updated 3 years ago
Alternatives and similar repositories for RunDotNetDll:
Users that are interested in RunDotNetDll are comparing it to the libraries listed below
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- Ruxcon2016 POC Code☆137Updated 8 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆34Updated 8 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆74Updated 10 years ago
- A simple API monitor for Windbg☆62Updated 7 years ago
- Frida.re based RunPE (and MapViewOfSection) extraction tool☆111Updated 7 years ago
- Sample use cases of the .NET native code hooking technique☆208Updated 7 years ago
- ☆213Updated 6 years ago
- Implementation of the .NET Profiler DLL hijack in C#☆98Updated 6 years ago
- Enumerate Windows Defender threat families and dump their names according category☆88Updated 5 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆148Updated 5 years ago
- Driver Initial Reconnaissance Tool☆121Updated 5 years ago
- Decodes PlugX traffic and encrypted/compressed artifacts☆38Updated 11 years ago
- Parsers for custom malware formats ("Funky malware formats")☆93Updated 3 years ago
- ☆107Updated 4 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago
- Go Lang Portable Executable Parser☆39Updated 3 years ago
- A tool to exploit .NET DCOM for EoP and RCE. Is fixed in latest versions of the .NET.☆87Updated 10 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆93Updated 3 years ago
- Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process.☆156Updated 5 years ago
- DLL Injection Library & Tools☆72Updated 8 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆83Updated 2 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- Bare template for a Kernel Mode Driver☆51Updated 4 years ago
- ☆113Updated 8 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆56Updated 6 years ago
- A Generic Windows Memory Scraping Tool☆70Updated 7 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- A proof of concept for dynamically loading .net assemblies at runtime with only a minimal convention pre-knowledge☆162Updated 6 years ago
- Script analysis tool based on Frida.re☆129Updated 7 years ago