huntandhackett / sysmon-indepth
Understanding the operation and limitations of Sysmon's events
☆14Updated 2 years ago
Alternatives and similar repositories for sysmon-indepth:
Users that are interested in sysmon-indepth are comparing it to the libraries listed below
- ☆16Updated last year
- A method to execute shellcode using RegisterWaitForInputIdle API.☆52Updated last year
- ☆52Updated 2 years ago
- Beacon Debugger☆40Updated 5 months ago
- ☆16Updated 7 months ago
- A work in progress BOF/COFF loader in Rust☆47Updated 2 years ago
- Repo that holds random POCs☆49Updated last year
- ☆21Updated 11 months ago
- Repository for dirty scripts and PoCs☆17Updated last month
- Load a dynamic library from memory using a fuse mount☆30Updated last year
- yet another sleep encryption thing. also used the default github repo name for this one.☆70Updated last year
- BYOVD collection☆23Updated last year
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆18Updated 3 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- rust clr heap encryption (https://github.com/lap1nou/CLR_Heap_encryption), but no heap encryption.☆15Updated last year
- Donut generator in rust.☆26Updated 3 years ago
- ☆43Updated last year
- Modified Version of Melkor @FuzzySecurity capable of creating disposable AppDomains in injected processes.☆27Updated 3 years ago
- A Dynamic MSBuild task to help with minor obfuscation of C# Binaries to evade static signatures on each compilation☆36Updated last year
- ☆60Updated 3 years ago
- Windows RPC example calling stubs generated from MS-LSAT and MS-LSAD☆26Updated last year
- x64 version☆30Updated 3 years ago
- Rust implementation of the Process Herpaderping☆24Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- ☆36Updated 2 years ago
- Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm☆13Updated 8 months ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆45Updated 2 months ago
- A COFF Loader written in Rust☆63Updated last week
- POC of PPID spoofing using NtCreateUserProcess with syscalls to create a suspended process and performing process injection by overwritti…☆40Updated 3 years ago
- A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP☆33Updated 3 years ago