Loader Pre-Technology, Main thread hijacking without using API, get ntdll and kernel32 handle without peb. 加载器前置技术,不使用API进行主线程劫持,不使用PEB获取ntdll和kernel32的地址。
☆94Jul 26, 2025Updated last year
Alternatives and similar repositories for NTR_loader
Users that are interested in NTR_loader are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Using DLL sideloading to hijack the exe main thread before starting it! 使用dll侧载在exe程序主线程启动之前劫持主线程。☆29Jul 25, 2025Updated last year
- C#快速添加删除mssql用户小工具☆22Aug 30, 2025Updated last year
- 寻找可利用的白文件☆563Aug 18, 2025Updated last year
- Resolve the issue of DLLmain function in white and black DLLs hanging when calling shellcode☆208May 28, 2024Updated 2 years ago
- ☆18Jun 16, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆165Oct 27, 2024Updated last year
- tsh多终端代理通信☆21Feb 26, 2025Updated last year
- A Blind EDR Project for Educational Purposes☆108Jan 18, 2025Updated last year
- Get sql server connection configuration information☆28Aug 26, 2024Updated 2 years ago
- 基于个人习惯使用C/C++的shellcode开发项目模板☆49Aug 20, 2024Updated 2 years ago
- Load CLR to get RWX 通过加载clr在自身内存中产生rwx空间☆21Sep 28, 2022Updated 3 years ago
- 重构Beacon☆166Aug 19, 2024Updated 2 years ago
- Stack integrity verification to Detect SleepMask or CallStack Spoofer☆56Jul 13, 2025Updated last year
- 使用Visral Studio开发ShellCode☆245Oct 11, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 主要用于隐藏进程真实路径,进程带windows真签名☆119Oct 15, 2024Updated last year
- 后渗透信息/密码/凭证收集工具☆307May 7, 2025Updated last year
- GateSentinel 是一个现代化的 C2 (Command and Control) 框架,专为安全研究和渗透测试设计。该项目采用 Go 语言开发服务端,C 语言开发客户端,提供了强大的远程控制和管理功能。☆289Jul 17, 2025Updated last year
- ScyllaHide custom version for ida9.x☆23Sep 5, 2025Updated 11 months ago
- Stealthy Payload loader with Anti-EDR Capabilities☆135Apr 21, 2025Updated last year
- 自动化找白文件,用于扫描 EXE 文件的导入表,列出导入的DLL文件,并筛选出非系统DLL,符合条件的文件将被复制到特定的 X64 或 X86 文件夹☆639Mar 24, 2026Updated 5 months ago
- Terminate AV/EDR processes by exploiting the vulnerable NsecSoft driver☆32Sep 15, 2025Updated 11 months ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆103Mar 20, 2023Updated 3 years ago
- 基于 OPSEC 的 CobaltStrike 后渗透自动化链☆451Mar 11, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- suo5的二开改进,一款高性能,代码标准的 HTTP 代理隧道工具☆78Sep 5, 2025Updated 11 months ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆76Mar 16, 2026Updated 5 months ago
- 一种通过进程注入实现强制关闭部分杀软进程的方法(以360安全卫士和360杀毒为例)☆142Dec 26, 2023Updated 2 years ago
- 一款基于PE Patch技术的后渗透免杀工具,主要支持x64☆350Mar 5, 2025Updated last year
- Use idapython create call topology, AI analysis function layer by layer. Get the target function conclusion.利用idapython创建函数调用拓扑,AI逐层分析函数,…☆25Jun 30, 2025Updated last year
- Process injection alternative☆408Sep 6, 2024Updated last year
- 在线安软识别☆12Aug 6, 2025Updated last year
- 通杀检测基于白文件patch黑代码的免杀技术的后门☆184Aug 3, 2024Updated 2 years ago
- EventViewer Bypass Uac Bof☆23Jul 23, 2022Updated 4 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- grs内网穿透工具通过reality协议隐藏特征☆628Aug 8, 2026Updated 3 weeks ago
- Run native PE or .NET executables entirely in-memory. Build the loader as an .exe or .dll—DllMain is Cobalt Strike UDRL-compatible☆276Jun 18, 2025Updated last year
- PoC for covert persistence via Windows Push Task Scheduler (WPTaskScheduler) RPC interface — invisible to schtasks, Get-ScheduledTask, an…☆74Jun 15, 2026Updated 2 months ago
- 一键提取exe的图标、嵌入图标、资源信息、版本信息、修改时间、数字签名,降低程序熵值☆437Dec 17, 2024Updated last year
- 命令执行写任意文件,主要用于命令执行但不出网情况☆31Sep 9, 2023Updated 2 years ago
- Pillager是一个适用于后渗透期间的信息收集工具☆1,294Sep 7, 2024Updated last year
- 自研C2 功能展示。cs+spark的结合体。省去了本地客户端,便于团队操作。后续开源社区版。☆16Oct 30, 2024Updated last year