hackerhouse-opensource / MarbleLinks
The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.
☆318Updated last year
Alternatives and similar repositories for Marble
Users that are interested in Marble are comparing it to the libraries listed below
Sorting:
- Offensive Lua.☆214Updated last week
- Analyse your malware to surgically obfuscate it☆502Updated 5 months ago
- ☆372Updated 2 years ago
- Inject DLLs into the explorer process using icons☆332Updated 6 months ago
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆416Updated 5 months ago
- ☆192Updated last year
- "AMSI WRITE RAID" Vulnerability that leads to an effective AMSI BYPASS☆309Updated last month
- Wordlist to crack .zip-file password☆206Updated 3 years ago
- ☆328Updated last month
- Win32 Shellcode CheatSheet: Your visual guide for crafting and understanding shellcode. Ideal for malware, and exploit developers☆63Updated last year
- CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administr…☆183Updated last year
- A project that demonstrates embedding shellcode payloads into image files (like PNGs) using Python and extracting them using C/C++. Paylo…☆209Updated 3 weeks ago
- Slides & Code snippets for a workshop held @ x33fcon 2024☆272Updated last year
- CIA UAC bypass implementation of Stinger that obtains the token from an auto-elevated process, modifies it, and reuses it to execute as A…☆301Updated last year
- Python implementation of GhostPack's Seatbelt situational awareness tool☆266Updated last year
- A delicious, but malicious SSL-VPN server 🌮☆252Updated last month
- Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework☆388Updated last year
- Self-spreading Java malware targeting Minecraft servers. Infected servers are capable of scanning for other vulnerable servers, encryptin…☆122Updated 10 months ago
- Nuke It From Orbit - remove AV/EDR with physical access☆271Updated 11 months ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆201Updated 7 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆137Updated last year
- ☆291Updated 2 years ago
- ☆132Updated 2 years ago
- ☆158Updated 5 months ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆362Updated 9 months ago
- Venom is a library that meant to perform evasive communication using stolen browser socket☆394Updated 2 years ago
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆249Updated 6 months ago
- I will be uploading all the codes which I created with the help either opensource projects or blogs. This is a step by step EDR learning …☆287Updated 3 months ago
- SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and up…☆254Updated last month
- AV/EDR Lab environment setup references to help in Malware development☆411Updated 9 months ago