mtth-bfft / ntsecLinks
Standalone tool to explore the security model of Windows and its NT kernel. Use it to introspect privilege assignments and access right assignments, enumerate attack surfaces from the point of view of a sandboxed process, etc.
☆33Updated 6 years ago
Alternatives and similar repositories for ntsec
Users that are interested in ntsec are comparing it to the libraries listed below
Sorting:
- Blog posts☆30Updated 5 years ago
- Process reimaging proof of concept code☆96Updated 6 years ago
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆39Updated 9 years ago
- ☆45Updated 7 years ago
- Reflective Polymorphism☆105Updated 7 years ago
- ☆34Updated 7 years ago
- ☆49Updated 5 years ago
- Windows Drivers☆99Updated 6 years ago
- DLL Injection Library & Tools☆71Updated 9 years ago
- PoC designed to evade userland-hooking anti-virus.☆89Updated 6 years ago
- CAPE monitor DLLs☆41Updated 5 years ago
- Windows Console Monitoring☆99Updated 7 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆96Updated 4 years ago
- A minimal tool to extract shellcode from 64-bit PE binaries.☆51Updated 3 years ago
- Analyze and attack windows applications using dll hijacking vulnerabilities☆58Updated 5 years ago
- a program to detect reflective dll injection on a live machine☆74Updated 9 years ago
- Simple 32/64-bit PEs loader.☆138Updated 6 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆76Updated 7 years ago
- The Minimalistic x86/x64 API Hooking Library for Windows☆32Updated 7 years ago
- Driver Initial Reconnaissance Tool☆123Updated 5 years ago
- Load a Windows Kernel Driver☆92Updated 8 years ago
- Evil Reflective DLL Injection Finder☆47Updated 6 years ago
- A tiny PoC to inject and execute code into explorer.exe with WM_SETTEXT+WM_COPYDATA+SetThreadContext☆50Updated 7 years ago
- ☆22Updated 4 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆56Updated 6 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆78Updated 9 years ago
- Malware Analysis, Anti-Analysis, and Anti-Anti-Analysis☆45Updated 7 years ago
- Enumerate Windows Defender threat families and dump their names according category☆90Updated 6 years ago
- C++☆80Updated 8 years ago