ngn13 / shrk
LKM rootkit for modern kernels, with DNS C2 and a simple web interface
ā64Updated this week
Alternatives and similar repositories for shrk:
Users that are interested in shrk are comparing it to the libraries listed below
- š”ļø A multi-user malleable C2 framework targeting Windows. Written in C++ and Pythonā43Updated 11 months ago
- stack spoofingā80Updated 3 months ago
- Dirty PoC on how to abuse S1's VEH for Vectored Syscalls and Local Executionā41Updated 7 months ago
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.ā90Updated 11 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.ā73Updated 6 months ago
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similarā125Updated 6 months ago
- TypeLib persistence techniqueā107Updated 3 months ago
- Threadless shellcode injection toolā63Updated 6 months ago
- BOF with Synthetic Stackframeā108Updated 3 weeks ago
- Execute dotnet app from unmanaged processā70Updated last month
- ā97Updated last year
- ā84Updated 6 months ago
- Malware?ā69Updated 4 months ago
- a demo module for the kaine agent to execute and inject assembly modulesā38Updated 5 months ago
- Exploiting the KsecDD Windows driver through Server Silosā50Updated 3 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assemblyā59Updated 11 months ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.ā62Updated last year
- ā60Updated 8 months ago
- Uses Threat-Intelligence ETW events to identify shellcode regions being hidden by fluctuating memory protectionsā114Updated last year
- a modified CONTEXT based ropchain to circumvent CFG-FindHiddenShellcode and EtwTi-FluctuationMonitorā93Updated 10 months ago
- Section-based payload obfuscation technique for x64ā59Updated 6 months ago
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already sā¦ā58Updated last year
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".ā78Updated last year
- ā51Updated last month
- ā122Updated 5 months ago
- Splitting and executing shellcode across multiple pagesā99Updated last year
- Implementing the ghostly hollowing PE injection technique using tampered syscalls.ā131Updated 8 months ago