An implementation of an indirect system call
☆133Aug 25, 2023Updated 2 years ago
Alternatives and similar repositories for PigSyscall
Users that are interested in PigSyscall are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆736Jul 19, 2023Updated 3 years ago
- more conveniently Visual-Studio-BOF-template☆76Sep 12, 2023Updated 2 years ago
- Self Cleanup in post-ex job☆60Sep 10, 2024Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆68May 2, 2023Updated 3 years ago
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆80Jul 23, 2023Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- beta☆120Sep 24, 2024Updated last year
- Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven☆270Oct 16, 2024Updated last year
- Porting of BOF InlineExecute-Assembly to load .NET assembly in process but with patchless AMSI and ETW bypass using hardware breakpoint.☆298Jun 12, 2026Updated last month
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆227Jul 25, 2023Updated 2 years ago
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆34Mar 17, 2023Updated 3 years ago
- .NET assembly loader with patchless AMSI and ETW bypass☆386Apr 19, 2023Updated 3 years ago
- 添加计划任务方法集合☆316Aug 6, 2023Updated 2 years ago
- Take a screenshot without injection for Cobalt Strike☆205Jun 7, 2023Updated 3 years ago
- A PoC implementation for dynamically masking call stacks with timers.☆314Feb 13, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE☆207Aug 25, 2023Updated 2 years ago
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆125Feb 13, 2023Updated 3 years ago
- 关于RPC一些绕EDR的tips☆201Mar 3, 2023Updated 3 years ago
- Process injection alternative☆408Sep 6, 2024Updated last year
- ☆46Jun 25, 2024Updated 2 years ago
- A beacon object file implementation of PoolParty Process Injection Technique.☆454Dec 21, 2023Updated 2 years ago
- C++ self-Injecting dropper based on various EDR evasion techniques.☆442Feb 11, 2024Updated 2 years ago
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆160Nov 7, 2023Updated 2 years ago
- A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk☆478Jul 6, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dumping LSASS with a duplicated handle from custom LSA plugin☆207Feb 23, 2022Updated 4 years ago
- Delete file regardless of whether the handle is used via SetFileInformationByHandle☆55Jul 1, 2023Updated 3 years ago
- A little tool to play with Windows security☆12Jan 21, 2026Updated 6 months ago
- Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms☆139Dec 20, 2022Updated 3 years ago
- Implementation of Indirect Syscall technique to pop a calc.exe☆110Jan 25, 2024Updated 2 years ago
- Syscall免杀☆509Jun 21, 2024Updated 2 years ago
- A BOF that runs unmanaged PEs inline☆700Oct 23, 2024Updated last year
- UDRL for CS☆440Dec 3, 2023Updated 2 years ago
- ☆85Nov 1, 2023Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Sleep Obfuscation☆839Dec 3, 2023Updated 2 years ago
- PE loader with various shellcode injection techniques☆454Oct 17, 2022Updated 3 years ago
- Its a coff loader ported to go( Modified by TimWhite )☆26Jul 17, 2023Updated 3 years ago
- Generic PE loader for fast prototyping evasion techniques☆247Jul 2, 2024Updated 2 years ago
- Cobalt Strike BOF that Add a user to localgroup by samr☆142Nov 30, 2022Updated 3 years ago
- Implant drop-in for EDR testing☆147Nov 15, 2023Updated 2 years ago
- Threadless Process Injection through entry point hijacking☆357Sep 10, 2024Updated last year