mobdk / CloneProcess
Clone running process with ZwCreateProcess
☆58Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for CloneProcess
- ☆17Updated 3 years ago
- ☆15Updated 3 years ago
- ☆98Updated 2 years ago
- ☆36Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- ☆24Updated last year
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆31Updated 3 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆44Updated 4 years ago
- Local OXID Resolver (LCLOR) : Research and Tooling☆33Updated 3 years ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆49Updated last year
- ☆57Updated 2 years ago
- Windows kernel PDB data parsed into YAML☆31Updated last week
- ☆27Updated 2 years ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆44Updated 7 years ago
- ☆76Updated 2 months ago
- A small commented POC for removing API hooks placed by AV/EDR.☆33Updated 4 years ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- ☆31Updated 4 years ago
- A compact tool for detecting AV/EDR hooks in default Windows libraries.☆29Updated 2 years ago
- A multi-staged malware that contains a kernel mode rootkit and a remote system shell.☆69Updated 3 years ago
- Process Injection without R/W target memory and without creating a remote thread☆19Updated 2 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆31Updated 2 years ago
- Rite Of Passage ROP Injector☆34Updated 5 years ago
- Sysmon shenanigans☆65Updated 4 years ago
- CSharp Writeups for HackSys Extreme Vulnerable Driver☆43Updated 2 years ago
- C Header Only Library for Virii☆9Updated 4 years ago