frkngksl / ParallelNimcalls
Nim version of MDSec's Parallel Syscall PoC
☆125Updated 3 years ago
Alternatives and similar repositories for ParallelNimcalls:
Users that are interested in ParallelNimcalls are comparing it to the libraries listed below
- COFF and BOF Loader written in Nim☆172Updated 2 years ago
- A quick example of the Hells Gate technique in Nim☆95Updated 3 years ago
- Indirect Syscalls: HellsGate in Nim, but making sure that all syscalls go through NTDLL (as in RecycledGate).☆181Updated 2 years ago
- NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs☆93Updated 2 years ago
- A tool for converting SysWhispers2 syscalls for use with Nim projects☆119Updated 3 years ago
- D/Invoke implementation in Nim☆100Updated 2 years ago
- Sleep obfuscation for shellcode implants and their reflective shit☆51Updated last year
- Implant drop-in for EDR testing☆135Updated last year
- ShellcodeFluctuation PoC ported to Nim☆75Updated 2 years ago
- Experiment on reproducing Obfuscate & Sleep☆143Updated 4 years ago
- PE Crypter written in Nim☆98Updated 4 years ago
- Overwrite a process's recovery callback and execute with WER☆103Updated 2 years ago
- A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading☆83Updated 2 years ago
- Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process☆100Updated 2 years ago
- PoC XLL builder in Python/Nim☆45Updated 2 years ago
- A Poc on blocking Procmon from monitoring network events☆100Updated 2 years ago
- Shellcode Injector that obtains system call opcodes using the Halo's Gate method to evade EDR Hooks.☆19Updated 3 years ago
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆133Updated 2 years ago
- It's pointy and it hurts!☆124Updated 2 years ago
- ☆133Updated last year
- ☆55Updated 3 years ago
- ☆136Updated 2 years ago
- Beacon Object File allowing creation of Beacons in different sessions.☆79Updated 2 years ago
- ☆72Updated 2 years ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆122Updated 2 years ago
- ☆142Updated 2 years ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆92Updated 3 years ago
- ☆162Updated 3 years ago
- A simple PoC to invoke an encrypted shellcode by using an hidden call☆116Updated 2 years ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆112Updated last year