f1rehaz4rd / Watchdog
DLL Injector as a service that watches the health of the started thread.
☆9Updated 4 years ago
Alternatives and similar repositories for Watchdog:
Users that are interested in Watchdog are comparing it to the libraries listed below
- ☆15Updated 4 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- Recreating and reviewing the Windows persistence methods☆37Updated 3 years ago
- A simple dumper as FreshyCalls' PoC. That's what's trendy, isn't it? ¯\_(ツ)_/¯☆39Updated 4 years ago
- A small commented POC for removing API hooks placed by AV/EDR.☆33Updated 4 years ago
- A tool to create COM class/interface relationships in neo4j☆47Updated 2 years ago
- Offensive Windows security tooling that allows for persistance to the operating system.☆10Updated 3 years ago
- C++ function that will automagically unhook a specified Windows API☆60Updated 4 years ago
- ☆31Updated 4 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆33Updated 3 years ago
- A C port of b33f's UrbanBishop☆38Updated 4 years ago
- ☆37Updated 3 years ago
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆54Updated 2 years ago
- ☆59Updated 2 years ago
- ☆14Updated 2 years ago
- ☆20Updated 3 years ago
- ☆69Updated last year
- Winlogon and LSA Notification Password Filters☆18Updated last year
- ☆36Updated 3 years ago
- Rite Of Passage ROP Injector☆34Updated 5 years ago
- A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP☆33Updated 3 years ago
- DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userla…☆120Updated 2 years ago
- Raw socket library/framework for red team events☆34Updated last year
- ☆24Updated 3 years ago
- A simple COM server which provides a component to run shellcode☆132Updated 4 years ago
- C code to enable ETW tracing for Dotnet Assemblies☆30Updated 2 years ago
- Injects shellcode into remote processes using direct syscalls☆74Updated 4 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆92Updated 3 years ago
- A collection of shellcode hashes☆17Updated 6 years ago