Alternative Read and Write primitives using Rtl* functions the unintended way.
☆79Aug 25, 2025Updated 6 months ago
Alternatives and similar repositories for RtlHijack
Users that are interested in RtlHijack are comparing it to the libraries listed below
Sorting:
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆138Apr 6, 2025Updated 11 months ago
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆50Jan 25, 2025Updated last year
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆37Aug 5, 2025Updated 7 months ago
- A reflective DLL development template for the Rust programming language☆116Nov 4, 2025Updated 4 months ago
- Vectored Exception Handling Squared☆30Dec 27, 2025Updated 2 months ago
- ☆26Aug 11, 2025Updated 6 months ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆117Jan 20, 2025Updated last year
- A way to maintain long-term access to Windows LAPS for lateral movement in AD via installing an Offensive LAPS RPC backdoor on a DC.☆29Jun 9, 2025Updated 9 months ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆103Feb 25, 2025Updated last year
- find dll base addresses without PEB WALK☆161Jul 13, 2025Updated 7 months ago
- Impersonate Tokens using only NTAPI functions☆84Apr 4, 2025Updated 11 months ago
- A Mythic agent for Windows written in C☆159Mar 1, 2026Updated last week
- early cascade injection PoC based on Outflanks blog post, in rust☆62Nov 8, 2024Updated last year
- ForsHops☆59Mar 25, 2025Updated 11 months ago
- An advanced utility for converting Windows Portable Executable (PE) files to position-independent code (PIC) shellcode. It enables execut…☆65Mar 1, 2025Updated last year
- converts sRDI compatible dlls to shellcode☆35Jan 20, 2025Updated last year
- Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls☆218Aug 31, 2025Updated 6 months ago
- A PoC for Early Cascade process injection technique.☆211Jan 30, 2025Updated last year
- 64-bit, position-independent implant template for Windows in Rust.☆175Nov 28, 2025Updated 3 months ago
- Sleep obfuscation