mannyfred / MentalTi
Mentally ill EtwTi parser
☆24Updated last week
Alternatives and similar repositories for MentalTi:
Users that are interested in MentalTi are comparing it to the libraries listed below
- Dynamically resolve API function addresses at runtime in a secure manner.☆46Updated 3 months ago
- A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.☆65Updated last month
- BOF for C2 framework☆40Updated 2 months ago
- Sample Rust Hooking Engine☆35Updated 9 months ago
- ☆83Updated 4 months ago
- stack spoofing☆74Updated 2 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆38Updated 4 months ago
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆105Updated 4 months ago
- A collection of position independent coding resources☆64Updated this week
- macOS dylib stager☆26Updated this week
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated last year
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆60Updated 10 months ago
- based on https://gitlab.com/ORCA000/snaploader☆42Updated last month
- A more reliable way of resolving syscall numbers in Windows☆50Updated 11 months ago
- A few examples of how to trap virtual memory access on Windows.☆18Updated last month
- A process injection technique using only thread context manipulation☆25Updated last year
- ☆96Updated last year
- Exploiting the KsecDD Windows driver through Server Silos☆37Updated 2 months ago
- shell code example☆17Updated last week
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆46Updated 4 months ago
- ☆27Updated 6 months ago
- Mythic C2 Agent written in x64 PIC C☆64Updated 2 weeks ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆29Updated 6 months ago
- ☆29Updated last month
- Execute dotnet app from unmanaged process☆67Updated 3 weeks ago
- early cascade injection PoC based on Outflanks blog post, in rust☆50Updated 2 months ago