jakydibe / Zone
☆16Updated this week
Alternatives and similar repositories for Zone
Users that are interested in Zone are comparing it to the libraries listed below
Sorting:
- a modified CONTEXT based ropchain to circumvent CFG-FindHiddenShellcode and EtwTi-FluctuationMonitor☆92Updated last year
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Execution☆42Updated 10 months ago
- A collection of position independent coding resources☆78Updated 3 months ago
- Malware?☆70Updated 7 months ago
- Proof of concept demonstrating a method of proxying syscalls indirectly☆8Updated 10 months ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆77Updated 2 months ago
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆95Updated last month
- ☆106Updated 4 months ago
- MIPS VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆114Updated 5 months ago
- Injecting DLL into LSASS at boot☆105Updated 2 weeks ago
- ForsHops☆44Updated last month
- shell code example☆49Updated this week
- 🧠 The ultimate, community-curated resource for Beacon Object Files (BOFs) — tutorials, how-tos, deep dives, and reference materials.☆66Updated 3 weeks ago
- ☆114Updated 2 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆74Updated 9 months ago
- Hooking KPRCB IdlePreselect function to gain execution inside PID 0.☆63Updated last month
- BOF with Synthetic Stackframe☆145Updated 2 months ago
- Shellcode Loader Utilizing ETW Events☆63Updated 2 months ago
- "Service-less" driver loading☆154Updated 5 months ago
- Collection of different rootkit functionality, each driver representing a different rootkit component☆10Updated 7 months ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆51Updated 3 months ago
- ForsHops☆131Updated last month
- Shellcode loader☆81Updated 5 months ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆65Updated last month
- stack spoofing☆84Updated 6 months ago
- ☆126Updated 8 months ago
- ☆30Updated 4 months ago
- converts sRDI compatible dlls to shellcode☆29Updated 3 months ago
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆120Updated 3 months ago
- A process injection technique using only thread context manipulation☆29Updated last year