Reproducing the SkeletonKey malware.
☆11Apr 6, 2024Updated 2 years ago
Alternatives and similar repositories for SkeletonKey
Users that are interested in SkeletonKey are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Offensive Assembly code snippets.☆13Jul 12, 2023Updated 3 years ago
- An example of Windows self-replicating malware.☆13Jan 16, 2023Updated 3 years ago
- Basic interactive Windows kernel offensive toolkit written in C☆137Sep 20, 2025Updated 10 months ago
- A kernel driver to get a Handle to virtually *every* process☆14Jan 16, 2024Updated 2 years ago
- Utilizing DLang For Offensive Operations.☆15May 29, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆121May 2, 2024Updated 2 years ago
- Reimplementation of the KExecDD DSE bypass technique.☆62Sep 7, 2024Updated last year
- Modifies machine.config for persistence after installing signed .net assembly onto GAC☆12Mar 17, 2022Updated 4 years ago
- Automated .NET AppDomain hijack payload generation☆129Feb 4, 2025Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆61May 12, 2025Updated last year
- A tracker DLL which enables 'NTAPI->Syscall' tracking whenever it is loaded. It calls 'NtSetInformationProcess' API call with a callback …☆14Oct 21, 2024Updated last year
- Convert binaries to shellcode (C, C#, CPP, ASM, BOF loader, PS to b64)☆19Jun 6, 2025Updated last year
- Tutorial covering how to discover DLLs for Hijacking and how to create proxy DLLS using Microsoft Teams as an example☆16Apr 7, 2021Updated 5 years ago
- ☆60Dec 15, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆12Feb 19, 2026Updated 5 months ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆46Jul 16, 2023Updated 3 years ago
- A step-by-step walkthrough of how to write a Client and a Driver to communicate with each other and boost the priority of a thread.☆18Dec 12, 2023Updated 2 years ago
- ☆30May 16, 2023Updated 3 years ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆140Jul 23, 2024Updated 2 years ago
- Contexter - A secondary context path traversal / server-side parameter pollution testing tool written in Python 3☆27Aug 18, 2024Updated last year
- Detect userland hooks placed by AV/EDR☆28Sep 4, 2023Updated 2 years ago
- Poshito is a Windows C2 over Telegram☆20Oct 30, 2024Updated last year
- CreateRemoteThreadPlus: how to pass multiple parameters to the remote thread function without shellcode.☆141Jul 10, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cisco CallManager User Enumeration☆15Aug 16, 2022Updated 3 years ago
- ☆24Apr 28, 2024Updated 2 years ago
- Rust port of kdmapper☆21Aug 24, 2021Updated 4 years ago
- ☆13Mar 21, 2024Updated 2 years ago
- Heap encryption in Nim☆21Aug 25, 2024Updated last year
- Listing UDP connections with remote address without sniffing.☆31Sep 26, 2023Updated 2 years ago
- Exploitation of process killer drivers☆205Oct 17, 2023Updated 2 years ago
- A pure C version of SymProcAddress☆29Mar 17, 2024Updated 2 years ago
- Detect Remote Local Credentials Dumping using a Shadow Snapshot☆32Jan 27, 2025Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆111Aug 21, 2024Updated last year
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆51Feb 29, 2024Updated 2 years ago
- improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys☆49Mar 10, 2023Updated 3 years ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆89Feb 11, 2024Updated 2 years ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆68May 2, 2023Updated 3 years ago
- 简单版的PE加载器☆13Aug 11, 2020Updated 5 years ago
- Sleep obfuscation for shellcode implants and their reflective shit☆55Sep 19, 2023Updated 2 years ago