SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update processes.
☆265Feb 2, 2026Updated 3 months ago
Alternatives and similar repositories for SetupHijack
Users that are interested in SetupHijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 9 months ago
- "Service-less" driver loading☆187Nov 28, 2024Updated last year
- Windows rootkit designed to work with BYOVD exploits☆221Jan 18, 2025Updated last year
- This is the tool to dump the LSASS process on modern Windows 11☆581Updated this week
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆55May 12, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Fast covert timing channel communication for inter-process and inter-processor communication on Windows systems.☆72Mar 24, 2026Updated 2 months ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 8 months ago
- Mythic C2 Agent written in x64 PIC C☆87Jan 29, 2025Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆61Sep 7, 2024Updated last year
- This code silently installs Chrome extensions on Mac, Windows, and Linux☆162Jul 22, 2025Updated 10 months ago
- A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass☆171Sep 22, 2025Updated 8 months ago
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆362Mar 17, 2026Updated 2 months ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆19Jun 26, 2025Updated 11 months ago
- Project for generating and identifying deceptive LNK files.☆338Mar 8, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆356Nov 19, 2024Updated last year
- Lateral movement with DCOM DLL hijacking☆178Jul 4, 2025Updated 10 months ago
- Internal Monologue BOF☆79Dec 28, 2024Updated last year
- Process Injection using Thread Name☆309Apr 18, 2025Updated last year
- early cascade injection PoC based on Outflanks blog post, in rust☆63Nov 8, 2024Updated last year
- Sleep obfuscation☆276Dec 13, 2024Updated last year
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆189Updated this week
- Bypass user-land hooks by syscall tampering via the Trap Flag☆139Aug 25, 2025Updated 9 months ago
- Proof of concept source code and misc files for my CVE-2025-21692 exploit, kernel version 6.6.75☆40Sep 16, 2025Updated 8 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- various methods of making API calls☆19Feb 1, 2025Updated last year
- A runtime for developing large-scale and complex shellcode.☆22May 3, 2026Updated 3 weeks ago
- Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection☆76Dec 26, 2025Updated 5 months ago
- ☆38Apr 15, 2025Updated last year
- Proof-of-Concept tool for extracting credential material from sessions on modern Windows systems.☆690May 9, 2026Updated 2 weeks ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆444Jun 27, 2025Updated 11 months ago
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread☆33Sep 24, 2025Updated 8 months ago
- Finding Truth in the Shadows☆129Jan 26, 2023Updated 3 years ago
- Evasion kit for Cobalt Strike☆30Jan 16, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Apr 14, 2025Updated last year
- Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By f…☆340May 4, 2026Updated 3 weeks ago
- Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms☆140Dec 20, 2022Updated 3 years ago
- ACL Viewer for Windows☆133May 4, 2025Updated last year
- a demo module for the kaine agent to execute and inject assembly modules☆41Aug 28, 2024Updated last year
- Rust crate to run commands as another user☆59Feb 12, 2026Updated 3 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆353Mar 21, 2026Updated 2 months ago