ngn13 / cerez
Cerez 😈 userland LD_PRELOAD rootkit
☆18Updated 4 months ago
Alternatives and similar repositories for cerez:
Users that are interested in cerez are comparing it to the libraries listed below
- ☆38Updated 8 months ago
- Windows C++ Implant for Exploration C2☆28Updated 2 weeks ago
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- A simple ExternalC2 POC for Havoc C2. Communicates over Notion using a custom python agent, handler and extc2 channel. Not operationally …☆84Updated 2 years ago
- Implementation of Indirect Syscall technique to pop a calc.exe☆96Updated last year
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆62Updated 9 months ago
- ☆68Updated last year
- Core Submodule of Exploration C2☆14Updated 2 weeks ago
- Winsocket for Cobalt Strike.☆97Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆82Updated last year
- ☆76Updated last year
- BYOVD collection☆23Updated 11 months ago
- ☆79Updated 10 months ago
- ☆36Updated 2 years ago
- ☆39Updated 2 years ago
- A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.☆109Updated 11 months ago
- Sliver agent rewritten in C++☆44Updated 6 months ago
- Simple LSASS Dumper created using C++ as an alternative to using Mimikatz memory dumper☆53Updated 10 months ago
- CVE-2024-40711-exp☆39Updated 4 months ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- Create Anti-Copy DRM Malware☆52Updated 6 months ago
- Explorer Persistence technique : Hijacking cscapi.dll order loading path and writing our malicious dll into C:\Windows\cscapi.dll , when …☆81Updated 2 years ago
- This repository contains a proof-of-concept exploit written in C++ that demonstrates the exploitation of a vulnerability affecting the Wi…☆77Updated 11 months ago
- Identify and exploit leaked handles for local privilege escalation.☆106Updated last year
- ☆61Updated 2 years ago
- Arbitrary File Delete in Windows Installer before 10.0.19045.2193☆29Updated 2 years ago
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆56Updated 2 months ago
- Golang implementation of @CCob's C# ThreadlessInject☆32Updated 9 months ago
- ☆67Updated last year
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆118Updated 2 years ago