An implementation of the Process Hollowing technique.
☆17Dec 13, 2020Updated 5 years ago
Alternatives and similar repositories for Process-Hollowing
Users that are interested in Process-Hollowing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Exploit Exercises for Security Researchers (arm, x86...)☆12May 10, 2019Updated 7 years ago
- ☆32Sep 24, 2021Updated 4 years ago
- Program to leak anti-virus behaviour and such☆14Apr 18, 2019Updated 7 years ago
- External Hooking ( Bypasss process byte patching checks | Injector included )☆22Mar 12, 2023Updated 3 years ago
- All Nt Syscall and W32k Syscall in one asm, include, and call it!☆58Nov 4, 2021Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆40Dec 31, 2020Updated 5 years ago
- The modifyed cjson that can running on windows kernel☆16Mar 21, 2023Updated 3 years ago
- Kernel-Mode driver and User-Mode application communication project☆12Jun 24, 2018Updated 8 years ago
- A kernel-mode rootkit with remote control☆225Nov 13, 2020Updated 5 years ago
- windows user mode network library☆11Jul 1, 2026Updated 3 weeks ago
- 基于UDP穿越非对称NAT建立P2P网络的Windows实现(UDP打洞)☆13Nov 6, 2019Updated 6 years ago
- With this RunPE you can easily inject your payload in any x86 or x64 program.☆16Jun 3, 2019Updated 7 years ago
- A simple packer working with all PE files which cipher your exe with a XOR implementation☆13Aug 10, 2020Updated 5 years ago
- An example of Windows self-replicating malware.☆13Jan 16, 2023Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Execute an arbitrary command within the context of another process☆21Jun 28, 2019Updated 7 years ago
- Windows system repair tool☆18Jun 2, 2021Updated 5 years ago
- Process Hollowing for 32 bit and 64 bit☆79Nov 10, 2017Updated 8 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆26Apr 21, 2022Updated 4 years ago
- A small set of functions for RE detection on x86_64 Linux☆15Jan 22, 2024Updated 2 years ago
- Simple PE Packer Which Encrypts .text Section☆50May 28, 2017Updated 9 years ago
- Simple proof of concept code for injecting libraries on 64bit processes from a 32bit process☆96Oct 12, 2018Updated 7 years ago
- DarkRat source - beware untested source and resources.☆21Dec 7, 2019Updated 6 years ago
- Register a callback from a Manually mapped kernel module☆16Feb 1, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Emulate Drivers in RING3 with self context mapping or unicorn☆21Jan 1, 2025Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆75Feb 11, 2024Updated 2 years ago
- Static Library For Windows Drivers☆42Jun 19, 2026Updated last month
- BetaShield Windows x86 Ring3 Anticheat v2☆46Jan 11, 2017Updated 9 years ago
- Windows process injection methods☆20Jul 18, 2021Updated 5 years ago
- An example of PE hollowing injection technique☆27Jun 28, 2019Updated 7 years ago
- C++ Compile time NAND/NOR obfuscation☆53Jan 27, 2020Updated 6 years ago
- Heaven's Gate implementation in C for constructing x64 Win32 API call in x86 WoW64 processes.☆82Nov 6, 2021Updated 4 years ago
- Basic utilities for executing, reading and writing 64-bit data in a 32-bit WoW64 process☆20Jul 8, 2022Updated 4 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 8086 Assembly Chess☆11Feb 11, 2019Updated 7 years ago
- ☆26Jul 15, 2023Updated 3 years ago
- Rootkit loader for your rootkit dll, x86/x64 system wide DLL injection (+appinit_dlls registry create) uses heavens gate☆23Jan 28, 2021Updated 5 years ago
- IDA plugin to explore and browse tags☆57Jul 19, 2019Updated 7 years ago
- RunPE using Hell's Gate technique.☆32Dec 4, 2020Updated 5 years ago
- Evasive Process Hollowing Techniques☆143Aug 16, 2020Updated 5 years ago
- A project on the Unicorn emulator to emulate the code of Pe files in windows☆27Sep 12, 2024Updated last year