malcomvetter / WMIProcessWatcher
An example pattern in C# for using WMI to monitor process creation and termination events.
☆51Updated 6 years ago
Related projects: ⓘ
- Uses WMI Event Win32_ModuleLoadTrace to monitor module loading. Provides filters, and detailed data. Has an option to monitor for CLR Inj…☆39Updated 5 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆31Updated 6 years ago
- Dump certificates from PE files in different formats☆36Updated 8 months ago
- Simple DLL injector written in C#☆24Updated 8 years ago
- ☆41Updated 5 years ago
- A ready-made template for a project based on libpeconv.☆40Updated last year
- Bare template for a Kernel Mode Driver☆50Updated 4 years ago
- PoC: Prevent a debugger from attaching to managed .NET processes via a watcher process code pattern.☆33Updated 6 years ago
- A simple POC to demonstrate the power of .NET debugging for injection☆71Updated 4 years ago
- ☆33Updated 5 years ago
- Hide .Net assembly into png images☆35Updated 5 years ago
- Windows x64 Process Scanner to detect application compatability shims☆37Updated 5 years ago
- Clone running process with ZwCreateProcess☆58Updated 3 years ago
- Minimalist Custom .NET Core Garbage Collector☆21Updated 4 years ago
- Library of tools and examples for loading/bootstrapping managed code from unmanaged code in .NET☆62Updated 4 years ago
- Send and receive messages over Named Pipes asynchronously.☆38Updated 3 years ago
- .NET project for writing files to local or remote hosts☆38Updated 4 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆73Updated 4 years ago
- Runs programs as TrustedInstaller☆43Updated 5 years ago
- Automate AV evasion by calling AMSI☆85Updated last year
- ☆26Updated last year
- Inject .Net payloads into other .Net assemblies on disk☆61Updated 4 years ago
- ☆36Updated 2 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 3 years ago
- Persistent through COM Hijacking☆20Updated 5 years ago
- Antivirus Emulator Fingerprints☆25Updated 5 years ago
- Quick Proof of Concept for reading a processes memory and searching for a specific string.☆10Updated 5 years ago
- ☆19Updated this week
- ☆33Updated 6 years ago
- Managed wrappers around the Windows API and some Native API☆32Updated 6 years ago