frkngksl / UnlinkDLL
DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable
☆57Updated last year
Alternatives and similar repositories for UnlinkDLL:
Users that are interested in UnlinkDLL are comparing it to the libraries listed below
- ☆58Updated last year
- A more reliable way of resolving syscall numbers in Windows☆50Updated 11 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆76Updated 5 months ago
- ☆45Updated 2 months ago
- miscellaneous codes☆35Updated last year
- ☆47Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- BOF for C2 framework☆40Updated 2 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆45Updated 10 months ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago
- A pure C version of SymProcAddress☆24Updated 10 months ago
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- in-process powershell runner for BRC4☆45Updated last year
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- EvtPsst☆54Updated last year
- ☆36Updated last year
- Windows Thread Pool Injection Havoc Implementation☆28Updated 9 months ago
- stack spoofing☆74Updated 2 months ago
- API Hammering with C++20☆43Updated 2 years ago
- ☆29Updated last month
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆46Updated 8 months ago
- Construct the payload at runtime using an array of offsets☆61Updated 7 months ago
- Find DLLs with RWX section☆76Updated last year
- Just another Process Injection using Process Hollowing technique.☆16Updated last year