hackerhouse-opensource / MarbleLinks
The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.
☆320Updated 2 years ago
Alternatives and similar repositories for Marble
Users that are interested in Marble are comparing it to the libraries listed below
Sorting:
- Analyse your malware to surgically obfuscate it☆512Updated 3 weeks ago
- RunPE implementation with multiple evasive techniques (1)☆376Updated 2 years ago
- Win32 Shellcode CheatSheet: Your visual guide for crafting and understanding shellcode. Ideal for malware, and exploit developers☆65Updated last year
- Offensive Lua.☆221Updated last month
- ☆192Updated last year
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆424Updated 7 months ago
- CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administr…☆182Updated 2 years ago
- Venom is a library that meant to perform evasive communication using stolen browser socket☆395Updated 2 years ago
- Wordlist to crack .zip-file password☆207Updated 3 years ago
- A delicious, but malicious SSL-VPN server 🌮☆257Updated 3 months ago
- A project that demonstrates embedding shellcode payloads into image files (like PNGs) using Python and extracting them using C/C++. Paylo…☆212Updated 2 months ago
- Inject DLLs into the explorer process using icons☆397Updated 7 months ago
- ☆329Updated 3 months ago
- Slides & Code snippets for a workshop held @ x33fcon 2024☆277Updated last year
- "AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS☆315Updated 3 months ago
- ☆132Updated 2 years ago
- Nuke It From Orbit - remove AV/EDR with physical access☆270Updated last year
- Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework☆388Updated last year
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆319Updated 2 years ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆137Updated 2 years ago
- LOLAPPS is a compendium of applications that can be used to carry out day-to-day exploitation.☆194Updated 10 months ago
- ☆157Updated 8 months ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆202Updated 9 months ago
- ☆161Updated 6 months ago
- CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as A…☆300Updated 2 years ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆123Updated last week
- ☆72Updated 11 months ago
- Self-spreading Java malware targeting Minecraft servers. Infected servers are capable of scanning for other vulnerable servers, encryptin…☆121Updated last year
- Tools for analyzing EDR agents☆273Updated last year
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆263Updated 8 months ago