nccgroup / WindowsPatchDetector
Experimental Windows .text section Patch Detector
☆21Updated 10 years ago
Alternatives and similar repositories for WindowsPatchDetector:
Users that are interested in WindowsPatchDetector are comparing it to the libraries listed below
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆29Updated 7 years ago
- PCAUSA Rawether for Windows Local Privilege Escalation☆38Updated 7 years ago
- My conference presentations and publications☆26Updated 2 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 6 years ago
- Malware analyses and helpful scripts☆29Updated 2 years ago
- ☆22Updated 4 years ago
- ☆28Updated 7 years ago
- PoC for Bypassing UM Hooks By Bruteforcing Intel Syscalls☆39Updated 9 years ago
- A new binary injection technique, can easily go through any #CIG protected process and slip through all possible defenses without any inj…☆17Updated 6 years ago
- ☆33Updated 7 years ago
- Public repository for HEVD exploits☆20Updated 6 years ago
- ☆12Updated 7 years ago
- ☆12Updated 8 years ago
- ☆16Updated 7 years ago
- ☆22Updated 7 years ago
- Old exploits and code for my self-referencing PML4 technique (2014)☆31Updated 9 years ago
- Notepad++ Syntax Highlighting for Languages Used by Cyber Security Professionals☆14Updated 4 years ago
- Will try to put here slides from now on when I give a talk☆24Updated 3 years ago
- An IDA Pro script for creating a clearer idb for nymaim malware☆10Updated 6 years ago
- Green shellcode challenge tools☆22Updated 5 years ago
- IDA Pro plugin that rename functions on load, based on functionality☆19Updated 6 years ago
- Protects and logs suspicious and malicious usage of .NET CSC.exe and Runtime C# Compilation☆25Updated 6 years ago
- Fuzzing Framework☆10Updated 7 years ago
- ☆10Updated 7 years ago
- Auto Inject Dll , it have three method to inject your custom dll. help you to test inject.☆9Updated 8 years ago
- ☆16Updated 4 years ago
- PowerShell Module Bindings for Capstone/Keystone☆24Updated 8 years ago
- Win32k Elevation of Privilege PocUpdated 5 years ago
- Experimental: Windows .text section compare - disk versus memory☆14Updated 10 years ago
- Anti-AV compilation☆42Updated 11 years ago