jackullrich / EmulateMe
Showing how proof-of-work can be used to evade antivirus emulators.
☆11Updated 4 months ago
Alternatives and similar repositories for EmulateMe:
Users that are interested in EmulateMe are comparing it to the libraries listed below
- Miscellaneous examples for use with Cobalt Strike Beacon☆10Updated 4 years ago
- C# code to run PIC using CreateThread☆17Updated 5 years ago
- ☆11Updated 5 years ago
- ☆21Updated 3 years ago
- ☆48Updated 3 years ago
- ☆24Updated 3 years ago
- C code to enable ETW tracing for Dotnet Assemblies☆31Updated 2 years ago
- ☆18Updated 3 years ago
- ☆15Updated last year
- A BOF for enumerating version information for DLLs associated for a Beacon process.☆15Updated 3 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆12Updated last year
- Proof-of-Concept to evade auditd by tampering via ptrace☆17Updated last year
- Loads .NET Assembly Via CLR Loader☆16Updated 6 years ago
- Dump Lsass Memory Using a Reflective Dll☆14Updated 3 years ago
- DoublePulsar (Position-Independent) Shellcode (Windows 7 SP1 x64)☆27Updated 5 years ago
- Silent Cleanup UAC Bypass POC☆11Updated 5 years ago
- A collection of scripts used to support an OffSecOps pipeline.☆14Updated 4 years ago
- Disable PPL via custom driver and dump lsass☆15Updated 4 years ago
- Some stuff for PHD2021☆13Updated 3 years ago
- A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.☆18Updated 3 years ago
- ☆9Updated 4 years ago
- A lexer and parser for Sleep☆16Updated 2 months ago
- leaking net-ntlm with webdav☆24Updated 4 years ago
- A C port of b33f's UrbanBishop☆38Updated 4 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 4 years ago
- A simple Linux in-memory .so loader☆29Updated 2 years ago
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆18Updated last year
- Strstr with user-supplied needle and filename as a BOF.☆32Updated 3 years ago
- LoadLibrary for offensive operations☆33Updated 3 years ago
- A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP☆33Updated 3 years ago