Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment variables. Dumps, detects and dissasemble hooks, shellcode, memory regions, modules and processes.
☆45Sep 22, 2024Updated last year
Alternatives and similar repositories for WhacAMole
Users that are interested in WhacAMole are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆14Nov 24, 2022Updated 3 years ago
- ☆11Feb 19, 2023Updated 3 years ago
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated 2 years ago
- Use hardware breakpoints to spoof the call stack for both syscalls and API calls☆206Jun 6, 2024Updated 2 years ago
- C# project to Reflectively load .Net assemblies in memory☆19Jun 19, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Cobalt Strike UDRL for memory scanner evasion.☆52Dec 4, 2023Updated 2 years ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆34Mar 20, 2023Updated 3 years ago
- CreateRemoteThreadPlus: how to pass multiple parameters to the remote thread function without shellcode.☆142Jul 10, 2025Updated last year
- NailaoLoader: Hiding Execution Flow via Patching☆24Feb 27, 2025Updated last year
- Protect your process like ntoskrnl.exe☆17Jul 8, 2023Updated 3 years ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆90May 17, 2023Updated 3 years ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆66Mar 19, 2024Updated 2 years ago
- ☆10Apr 19, 2026Updated 3 months ago
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆142May 17, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Execute a payload at each right click on a file/folder in the explorer menu for persistence☆173Mar 15, 2023Updated 3 years ago
- Some stuff for PHD2021☆14May 21, 2025Updated last year
- BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detectio…☆18Jun 22, 2023Updated 3 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆42Jul 9, 2023Updated 3 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆35May 8, 2023Updated 3 years ago
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆19Jun 20, 2025Updated last year
- Memory API proxy via signed mozglue.dll☆39Jun 25, 2026Updated last month
- A simple PoC to invoke an encrypted shellcode by using an hidden call☆115Nov 19, 2022Updated 3 years ago
- Detect EDR's exceptions by inspecting processes' loaded modules☆133Mar 15, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆195Nov 27, 2024Updated last year
- TCP Data Transfer Tool By ClumsyLulz☆11Feb 25, 2023Updated 3 years ago
- Yet another llvm based obfuscator based on goron.☆15May 23, 2026Updated 2 months ago
- it's a driver injector or driver loader header lib(Windows)☆13Aug 5, 2023Updated 3 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆100Feb 28, 2023Updated 3 years ago
- ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detecti…☆322Mar 20, 2024Updated 2 years ago
- Change hash for a signed pe☆18Jul 18, 2023Updated 3 years ago
- eXtensiable Malware Toolkit: Full Featured Golang C2 Framework with Awesome Features☆102Jul 29, 2026Updated 2 weeks ago
- The repository contains three lists. You only need to use one. Global proxy list or proxy list from RU, BU, KZ or proxy list by RU region☆10Mar 27, 2026Updated 4 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 学习windows驱动相关☆24Jul 31, 2019Updated 7 years ago
- Dump the memory of any PPL with a Userland exploit chain☆353Mar 17, 2023Updated 3 years ago
- Inject unsigned DLL into Protected Process Light (PPL)☆42May 8, 2025Updated last year
- Convert native dll to shellcode, and support exported function☆24Feb 10, 2021Updated 5 years ago
- Reduce Dynamic Analysis Detection Rates With Built-In Unhooker, Anti Analysis Techniques, And String Obfuscator Modules.☆21Dec 21, 2022Updated 3 years ago
- Implementation of ITaskHandler in C++☆15Feb 11, 2023Updated 3 years ago
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆66Sep 15, 2022Updated 3 years ago