lleon1435 / birdnet-pocLinks
Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.
☆14Updated 2 years ago
Alternatives and similar repositories for birdnet-poc
Users that are interested in birdnet-poc are comparing it to the libraries listed below
Sorting:
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- Internal Monologue BOF☆79Updated last year
- Find DLLs with RWX section☆80Updated 2 years ago
- Section-based payload obfuscation technique for x64☆64Updated last year
- A more reliable way of resolving syscall numbers in Windows☆54Updated last year
- ☆100Updated last year
- RPC to WebClient startup☆54Updated 5 months ago
- BOF for C2 framework☆44Updated last year
- Windows Thread Pool Injection Havoc Implementation☆32Updated last year
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated 11 months ago
- Impersonate Tokens using only NTAPI functions☆83Updated 9 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆83Updated last year
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆42Updated this week
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- A collection of position independent coding resources☆106Updated 2 months ago
- EvtPsst☆55Updated 2 years ago
- Sniffing files generator☆60Updated 11 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Updated 3 weeks ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆101Updated 3 weeks ago
- in-process powershell runner for BRC4☆48Updated 2 years ago
- A process injection technique using only thread context manipulation☆40Updated 2 years ago
- Modern PIC implant for Windows (64 & 32 bit)☆105Updated 6 months ago
- Blog/Journal on how to backdoor VSCode extensions☆76Updated 6 months ago
- ☆61Updated 2 years ago
- ☆47Updated 2 years ago
- Some of the presentations, workshops, and labs I gave at public conferences.☆34Updated 3 months ago
- Examples of various container types for Python and Golang☆16Updated 5 months ago
- use python on windows with full submodule support without installation☆30Updated last year
- Mythic C2 Agent written in x64 PIC C☆84Updated last year
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆66Updated 11 months ago