jackullrich / EmulateMeLinks
Showing how proof-of-work can be used to evade antivirus emulators.
☆11Updated 7 months ago
Alternatives and similar repositories for EmulateMe
Users that are interested in EmulateMe are comparing it to the libraries listed below
Sorting:
- Silent Cleanup UAC Bypass POC☆11Updated 5 years ago
- Miscellaneous examples for use with Cobalt Strike Beacon☆10Updated 4 years ago
- ☆12Updated 5 years ago
- ☆15Updated last year
- Dump Lsass Memory Using a Reflective Dll☆14Updated 3 years ago
- C# code to run PIC using CreateThread☆17Updated 6 years ago
- ☆21Updated 4 years ago
- ☆48Updated 4 years ago
- C code to enable ETW tracing for Dotnet Assemblies☆31Updated 2 years ago
- ☆18Updated 3 years ago
- ☆24Updated 3 years ago
- leaking net-ntlm with webdav☆25Updated 4 years ago
- Unamanged PS with Named Pipes☆9Updated 4 years ago
- A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.☆19Updated 3 years ago
- SSDP Service Discovery☆17Updated 6 years ago
- A BOF for enumerating version information for DLLs associated for a Beacon process.☆15Updated 3 years ago
- DoublePulsar (Position-Independent) Shellcode (Windows 7 SP1 x64)☆27Updated 5 years ago
- Some stuff for PHD2021☆14Updated last month
- ☆29Updated 4 years ago
- Proof-of-Concept to evade auditd by tampering via ptrace☆17Updated last year
- ☆15Updated 5 years ago
- A collection of scripts used to support an OffSecOps pipeline.☆14Updated 4 years ago
- Loads .NET Assembly Via CLR Loader☆16Updated 6 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆12Updated 2 years ago
- A proof-of-concept tool that attempts to retrieve the configuration from the memory dump of an F-Secure C3 Relay executable.☆18Updated 3 years ago
- Disable PPL via custom driver and dump lsass☆15Updated 4 years ago
- Example of async client/server sockets in .NET 5☆17Updated 4 years ago
- ☆25Updated 2 years ago
- Modifies machine.config for persistence after installing signed .net assembly onto GAC☆13Updated 3 years ago
- Just another casual shellcode native loader☆24Updated 3 years ago