mandiant / flare-kscldr
FLARE Kernel Shellcode Loader
☆176Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for flare-kscldr
- Process reimaging proof of concept code☆95Updated 5 years ago
- ☆107Updated 4 years ago
- ☆229Updated 7 years ago
- Driver Initial Reconnaissance Tool☆119Updated 4 years ago
- Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process.☆155Updated 5 years ago
- Parsers for custom malware formats ("Funky malware formats")☆92Updated 2 years ago
- A C/C++ implementation of Microsoft's Antimalware Scan Interface☆170Updated 6 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆133Updated 7 years ago
- Shellcode emulator written with Unicorn Framework With Process Dump Emulation Environment☆117Updated 4 years ago
- a program to detect reflective dll injection on a live machine☆74Updated 8 years ago
- ☆68Updated 2 years ago
- This respository is a collection of C# class libraries which implement RPC clients for various versions of the Windows Operating System f…☆269Updated 4 years ago
- Proxy system calls over an RPC channel☆96Updated 2 years ago
- ☆112Updated 8 years ago
- A tool to exploit .NET DCOM for EoP and RCE. Is fixed in latest versions of the .NET.☆87Updated 10 years ago
- Demos of various (also non standard) persistence methods used by malware☆218Updated last year
- Windows RPC Python fuzzer☆155Updated 6 years ago
- This is a simple example and explanation of obfuscating API resolution via hashing☆228Updated 4 years ago
- Simple 32/64-bit PEs loader.☆136Updated 5 years ago
- Simple library to spray the Windows Kernel Pool☆104Updated 4 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆147Updated 5 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆98Updated 5 years ago
- Windows Drivers☆95Updated 5 years ago
- Windows NT ioctl bruteforcer and modular fuzzer☆119Updated 5 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 7 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆147Updated 2 years ago