mtth-bfft / ntsecLinks
Standalone tool to explore the security model of Windows and its NT kernel. Use it to introspect privilege assignments and access right assignments, enumerate attack surfaces from the point of view of a sandboxed process, etc.
☆33Updated 6 years ago
Alternatives and similar repositories for ntsec
Users that are interested in ntsec are comparing it to the libraries listed below
Sorting:
- Process reimaging proof of concept code☆97Updated 6 years ago
- Blog posts☆29Updated 5 years ago
- Load a Windows Kernel Driver☆94Updated 8 years ago
- DLL Injection Library & Tools☆73Updated 9 years ago
- Windows Drivers☆100Updated 6 years ago
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆39Updated 10 years ago
- PoC designed to evade userland-hooking anti-virus.☆90Updated 6 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆99Updated 4 years ago
- Reflective Polymorphism☆109Updated 7 years ago
- a program to detect reflective dll injection on a live machine☆76Updated 10 years ago
- ☆51Updated 5 years ago
- ☆46Updated 7 years ago
- C++☆87Updated 9 years ago
- Driver Initial Reconnaissance Tool☆126Updated 6 years ago
- ☆34Updated 8 years ago
- A tiny PoC to inject and execute code into explorer.exe with WM_SETTEXT+WM_COPYDATA+SetThreadContext☆53Updated 7 years ago
- CAPE monitor DLLs☆41Updated 6 years ago
- Simple 32/64-bit PEs loader.☆139Updated 7 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆45Updated 4 years ago
- Gozi-MBR-rootkit Bootkit Modified☆69Updated 9 years ago
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆45Updated 8 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆59Updated 6 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆58Updated 7 years ago
- ☆23Updated 5 years ago
- A simple API monitor for Windbg☆65Updated 8 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆57Updated 9 years ago
- The Minimalistic x86/x64 API Hooking Library for Windows☆34Updated 7 years ago
- Bypass antivirus with dynamic import. Hide the api(s) used.☆28Updated 9 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆139Updated 8 years ago
- Sysmon shenanigans☆66Updated 5 years ago