mobdk / CloneProcess
Clone running process with ZwCreateProcess
☆58Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for CloneProcess
- ☆17Updated 3 years ago
- ☆98Updated 2 years ago
- ☆36Updated 2 years ago
- Windows kernel PDB data parsed into YAML☆31Updated 10 months ago
- ☆15Updated 3 years ago
- ☆76Updated 2 months ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆44Updated 7 years ago
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- ☆27Updated 2 years ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆30Updated 2 years ago
- Manually perform syscalls without going through any external API or DLL.☆16Updated last year
- Local OXID Resolver (LCLOR) : Research and Tooling☆33Updated 3 years ago
- A small commented POC for removing API hooks placed by AV/EDR.☆33Updated 4 years ago
- ☆24Updated 11 months ago
- SharpASM is a C# project that aims to automate ASM (i.e. shellcode) execution in .NET programs by exploiting code caves in RWX sections a…☆57Updated 2 years ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- ☆31Updated 4 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 2 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆44Updated 4 years ago
- A ready-made template for a project based on libpeconv.☆40Updated 2 weeks ago
- A kernel mode Windows rootkit in development.☆49Updated 2 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆31Updated 2 years ago
- Example for PagedOut!☆24Updated 5 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆110Updated 3 years ago
- A compact tool for detecting AV/EDR hooks in default Windows libraries.☆29Updated 2 years ago