nospaceships / raw-socket-sniffer
Packet capture on Windows without a kernel driver
☆187Updated 6 years ago
Alternatives and similar repositories for raw-socket-sniffer
Users that are interested in raw-socket-sniffer are comparing it to the libraries listed below
Sorting:
- Tool for injecting a "TCP Relay" managed assembly into unmanaged processes☆116Updated 5 years ago
- Position Independent Windows Shellcode Written in C☆291Updated 6 years ago
- Zerokit/GAPZ rootkit (non buildable and only for researching)☆182Updated 6 years ago
- DLL Injection tool to unlock guest VMs☆235Updated 12 years ago
- An attempt at Process Doppelgänging☆182Updated 7 years ago
- A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use…☆118Updated 7 years ago
- Windows Console Monitoring☆99Updated 7 years ago
- An improvement of the original reflective DLL injection technique by Stephen Fewer of Harmony Security☆324Updated 7 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆181Updated 8 years ago
- Capcom Rootkit POC☆194Updated 8 years ago
- Binaries, PowerShell scripts and information about Digital Signature Hijacking.☆216Updated 7 years ago
- A C/C++ implementation of Microsoft's Antimalware Scan Interface☆182Updated 7 years ago
- Universal Unhooking☆321Updated 6 years ago
- Extract Windows Defender database from vdm files and unpack it☆440Updated 5 years ago
- Windows DPAPI laboratory☆91Updated 7 years ago
- Tools for instrumenting Windows Defender's mpengine.dll☆295Updated 6 years ago
- VBS Reversed TCP Meterpreter Stager☆87Updated 7 years ago
- DC25 5A1F - Demystifying Windows Kernel Exploitation by Abusing GDI Objects☆145Updated 7 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆151Updated 5 years ago
- A General Purpose DLL & Code Injection Utility☆154Updated 7 years ago
- Live hunting of code injection techniques☆382Updated 5 years ago
- Use CLR to inject all the .NET apps☆184Updated 4 years ago
- AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.☆387Updated 5 years ago
- a tool to make it easy and fast to test various forms of injection☆173Updated 6 years ago
- Patching ROP-encoded shellcodes into PEs☆185Updated 7 years ago
- FLARE Kernel Shellcode Loader☆177Updated 6 years ago
- A list of ways to execute code on Windows using legitimate Windows tools☆307Updated 5 years ago
- Simple 32/64-bit PEs loader.☆138Updated 6 years ago
- This is a simple example and explanation of obfuscating API resolution via hashing☆235Updated 4 years ago
- ChimeraPE (a PE injector type - alternative to: RunPE, ReflectiveLoader, etc) - a template for manual loading of EXE, loading imports pay…☆223Updated 2 years ago