kargisimos / detenv
A small and portable Windows C library for sandbox detection
☆33Updated last year
Alternatives and similar repositories for detenv:
Users that are interested in detenv are comparing it to the libraries listed below
- ☆46Updated 2 years ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆76Updated 3 months ago
- Tool to aid in dumping LSASS process remotely☆38Updated 6 months ago
- Winsocket for Cobalt Strike.☆97Updated last year
- ☆80Updated 8 months ago
- ☆63Updated last year
- ☆54Updated 3 months ago
- in-process powershell runner for BRC4☆44Updated last year
- I have documented all of the AMSI patches that I learned till now☆71Updated last year
- SAM Dumping in C#☆41Updated last month
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆62Updated last month
- RCE PoC for Empire C2 framework <5.9.3☆25Updated 11 months ago
- C++ Staged Shellcode Loader with Evasion capabilities.☆79Updated 4 months ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆44Updated last month
- A method to execute shellcode using RegisterWaitForInputIdle API.☆52Updated last year
- DFSCoerce exe revisited version with custom authentication☆38Updated last year
- ☆52Updated 3 months ago
- Duplicate not owned Token from Running Process☆72Updated last year
- Exploit for CVE-2023-27532 against Veeam Backup & Replication☆106Updated last year
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 4 months ago
- ☆79Updated 10 months ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆99Updated last year
- CVE-2024-40711-exp☆38Updated 3 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆92Updated last year
- ProcExp Driver (Ab)use☆20Updated 2 years ago
- A repository with my code snippets for research/education purposes.☆49Updated last year
- Create Anti-Copy DRM Malware☆52Updated 5 months ago
- A remote unauthenticated DOS POC exploit that targets the authentication implementation of Havoc.☆34Updated last year
- malleable profile generator GUI for Havoc☆56Updated last year
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆72Updated 2 years ago