nbaertsch / nimvokeLinks
Indirect syscalls + DInvoke made simple.
☆94Updated 9 months ago
Alternatives and similar repositories for nimvoke
Users that are interested in nimvoke are comparing it to the libraries listed below
Sorting:
- malware written for educational purposes☆67Updated 11 months ago
- Writing Nimless Nim - Slides and source for BSIDESKC 2024 talk.☆85Updated 3 months ago
- NimReflectiveLoader is a Nim-based tool for in-memory DLL execution using Reflective DLL Loading.☆30Updated last year
- Sleep obfuscation for shellcode implants and their reflective shit☆52Updated 2 years ago
- Internal Monologue BOF☆74Updated 9 months ago
- PoC XLL builder in Python/Nim☆47Updated 2 years ago
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆160Updated 2 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆125Updated last month
- Permanently disable EDRs as local admin☆117Updated this week
- A hoontr must hoont☆98Updated 2 months ago
- Sample Rust Hooking Engine☆36Updated last year
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆81Updated 7 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆115Updated last week
- A collection of position independent coding resources☆93Updated last month
- Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking☆131Updated 3 months ago
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆51Updated 4 months ago
- adws enumeration bof☆137Updated last week
- A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure.☆102Updated last month
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated 8 months ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆101Updated 6 months ago
- A process injection technique using only thread context manipulation☆38Updated last year
- Installing wazuh SIEM Unified XDR and SIEM protection☆31Updated 4 months ago
- Impersonate Tokens using only NTAPI functions☆80Updated 6 months ago
- ForsHops☆149Updated 6 months ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆98Updated 2 years ago
- Lateral Movement Bof with MSI ODBC Driver Install☆106Updated last week
- Find DLLs with RWX section☆81Updated 2 years ago
- ☆135Updated 8 months ago
- Automated .NET AppDomain hijack payload generation☆127Updated 8 months ago
- A small How-To on creating your own weaponized WSL file☆118Updated 2 months ago