mzakyz666 / WikiLeaks-Marble-CIA
Clone repository for Source Code secret anti-forensic tools Marble Framework CIA, Leaked by WikiLeaks.
☆30Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for WikiLeaks-Marble-CIA
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆26Updated 6 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 2 months ago
- Program to leak anti-virus behaviour and such☆14Updated 5 years ago
- A Win32 PE/Executable Crypter that employs on the fly encryption & decryption of memory☆33Updated 10 years ago
- GreenKit is an userland rootkit hiding its own files and mining bitcoins on compromised computers. Do /NOT/ download or use this rootkit …☆41Updated 6 years ago
- Simple remote administration tool. Written in c++ and MASM.☆18Updated 6 years ago
- Windows GPU rootkit PoC by Team Jellyfish☆35Updated 9 years ago
- Simple library to handle PE files loading, relocating, get/set data, ..., in addition to process handling☆30Updated 5 years ago
- This is a tutorial and introduction to Reflective DLL Injection + reading outputs of injected dll using named pipes.☆18Updated 3 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆18Updated 8 years ago
- Ammyy v3 Source Code leak , with ❤️ <3☆36Updated 7 years ago
- Kernel mode windows NT API logger☆21Updated 5 years ago
- Proof of concept memory anti-forensic toolkit designed for hiding various artifacts inside the memory dump during memory acquisition on M…☆10Updated 5 years ago
- Sysprep Volatile Environment LPE (2017)☆13Updated 2 years ago
- Debugger checks in 3 ways☆20Updated 6 years ago
- Enter Product Key Volatile Environment LPE☆11Updated 2 years ago
- ☆21Updated 3 years ago
- using the Recycle Bin to insure persistence☆11Updated 2 years ago
- A tool that reads a PE file from a byte array buffer and injects it into memory.☆27Updated 5 years ago
- TaskMgr Volatile Environment LPE☆12Updated 2 years ago
- PoC for detecting and dumping process hollowing code injection☆50Updated 6 years ago
- Small class to help perform syscalls.☆21Updated last year
- Component Services Volatile Environment LPE☆11Updated 2 years ago
- A ready-made template for a project based on libpeconv.☆41Updated last month
- User-mode part of Zerokit platform☆20Updated 5 years ago
- Reverse Windows shell over TLS☆18Updated 8 years ago
- A packed & protected Module Loader and more, for 64-bit Windows☆28Updated 3 years ago
- vmware-backdoor☆33Updated 3 years ago