malcomvetter / ProtectProcessFromJoeUser
PoC: Protecting Joe User from killing his own process.
☆9Updated 6 years ago
Alternatives and similar repositories for ProtectProcessFromJoeUser:
Users that are interested in ProtectProcessFromJoeUser are comparing it to the libraries listed below
- PoC: process watcher patterns to make killing a process hard.☆11Updated 6 years ago
- An example in C# for programmatically calling UAC to escalate to admin☆14Updated 6 years ago
- C# Exe that can remotely retrieve C# assemblies for in-memory execution☆19Updated 6 years ago
- Managed wrappers around the Windows API and some Native API☆34Updated 6 years ago
- The evolution of NxRansomware☆10Updated 5 years ago
- POC runtime crypter☆9Updated 6 years ago
- PoC of a protected process causing a blue screen if killed.☆15Updated 6 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆52Updated 6 years ago
- Anti-Debug methods with C#☆14Updated 4 years ago
- Dump certificates from PE files in different formats☆38Updated last year
- Lightweight licensing library for .NET applications which allows the managing of licenses via web based scripts and on-the-fly code compi…☆15Updated 4 years ago
- Hide .Net assembly into png images☆35Updated 5 years ago
- Example managed and unmanaged plugins for CoreHook☆14Updated 6 years ago
- PoC: Prevent a debugger from attaching to managed .NET processes via a watcher process code pattern.☆32Updated 6 years ago
- Secured network tunnel for two computers connection☆32Updated 4 years ago
- CreateProcessAsUser experiments☆6Updated 8 years ago
- CVE-2019-1064 Local Privilege Escalation Vulnerability☆11Updated 5 years ago
- Quick Proof of Concept for reading a processes memory and searching for a specific string.☆10Updated 6 years ago
- ☆40Updated 12 years ago
- ☆15Updated 8 years ago
- .net debugger / msil interpreter / emulator☆16Updated 6 years ago
- Hide code from dnSpy and other C# spying tools☆41Updated 4 years ago
- Inject Frida-Gadget into a local process☆24Updated 5 years ago
- Win32 memory leak detector with ETW☆41Updated 7 years ago
- A collection of plugins for Babel Obfuscator☆13Updated 3 years ago
- Provides a way which you can load a .NET dll/exe from disk, modify/inject IL, and then run the assembly all in memory without modifying t…☆29Updated 7 years ago
- Plugin Driven Remote Administration Tool (Unsupported)☆13Updated 9 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆31Updated 7 years ago
- ☆10Updated 4 years ago
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆40Updated 5 years ago