enkomio / RunDotNetDll
A simple utility to list all methods of a given .NET Assembly and to invoke them
☆71Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for RunDotNetDll
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 7 years ago
- Implementation of the .NET Profiler DLL hijack in C#☆97Updated 5 years ago
- Sample use cases of the .NET native code hooking technique☆201Updated 6 years ago
- A simple API monitor for Windbg☆62Updated 7 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆147Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆73Updated 10 years ago
- Dynamic PowerShell Analysis Framework Based Upon PowerShell Debugging Functionality☆82Updated last year
- ☆213Updated 6 years ago
- Ruxcon2016 POC Code☆137Updated 7 years ago
- Telsy CTI Research Team☆57Updated 3 years ago
- Driver Initial Reconnaissance Tool☆119Updated 4 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆33Updated 8 years ago
- Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process.☆155Updated 5 years ago
- A proof of concept for dynamically loading .net assemblies at runtime with only a minimal convention pre-knowledge☆162Updated 6 years ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- Simple packer for arbitrary data using only .NET API calls. Produces a unique signature with every usage. Standalone program and library.…☆89Updated 5 years ago
- Hollow Process / Dynamic Forking / RunPE injection technique implemented in Python☆52Updated 3 years ago
- Bare template for a Kernel Mode Driver☆51Updated 4 years ago
- ☆134Updated 5 years ago
- Decodes PlugX traffic and encrypted/compressed artifacts☆38Updated 11 years ago
- A tool to exploit .NET DCOM for EoP and RCE. Is fixed in latest versions of the .NET.☆87Updated 10 years ago
- Sacara VM☆122Updated 4 years ago
- Go Lang Portable Executable Parser☆37Updated 3 years ago
- ☆107Updated 4 years ago
- C# code to run shellcode in a sneaky way☆89Updated 4 years ago
- ANBU (Automatic New Binary Unpacker) a tool for me to learn about PIN and about algorithms for generic unpacking.☆88Updated 5 years ago
- Flare-On solutions☆36Updated 5 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆93Updated 6 years ago