hasherezade / demos
Demos of various injection techniques found in malware
☆791Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for demos
- A memory scanning evasion technique☆839Updated 7 years ago
- ☆798Updated 4 years ago
- makin - reveal anti-debugging and anti-VM tricks [This project is not maintained anymore]☆732Updated 5 years ago
- A set of tutorials about code injection for Windows.☆305Updated 2 months ago
- Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)☆792Updated 2 years ago
- Portable Executable parsing library (from PE-bear)☆648Updated 2 months ago
- InjectProc - Process Injection Techniques [This project is not maintained anymore]☆994Updated 5 years ago
- Shellcode Compiler☆1,065Updated 2 months ago
- Driver loader for bypassing Windows x64 Driver Signature Enforcement☆1,045Updated 5 years ago
- My implementation of enSilo's Process Doppelganging (PE injection technique)☆580Updated 2 years ago
- Converts a DLL into EXE☆796Updated last year
- Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits☆360Updated 4 years ago
- Obfuscate specific windows apis with different apis☆982Updated 3 years ago
- WinDBG Anti-RootKit Extension☆615Updated 4 years ago
- A library to load, manipulate, dump PE files. See also: https://github.com/hasherezade/libpeconv_tpl☆1,121Updated 3 weeks ago
- Virtualbox, VirtualMachine, Cuckoo, Anubis, ThreatExpert, Sandboxie, QEMU, Analysis Tools Detection Tools☆442Updated 6 years ago
- Kernel rootkit, that lives inside the Windows registry values data☆488Updated 7 years ago
- metame is a metamorphic code engine for arbitrary executables☆569Updated 5 years ago
- Windows process injection methods☆143Updated last year
- PowerLoaderEx - Advanced Code Injection Technique for x32 / x64☆359Updated 7 years ago
- windows syscall table from xp ~ 10 rs4☆349Updated 6 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆581Updated 7 years ago
- ☆393Updated 7 years ago
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆515Updated 2 years ago
- Post-exploitation tool for hiding processes from monitoring applications☆721Updated last year
- A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager☆646Updated 5 years ago
- ☆518Updated 6 years ago
- zer0m0n driver for cuckoo sandbox☆356Updated 9 years ago