nospaceships / raw-socket-sniffer
Packet capture on Windows without a kernel driver
☆183Updated 6 years ago
Alternatives and similar repositories for raw-socket-sniffer:
Users that are interested in raw-socket-sniffer are comparing it to the libraries listed below
- Tool for injecting a "TCP Relay" managed assembly into unmanaged processes☆116Updated 5 years ago
- An attempt at Process Doppelgänging☆184Updated 7 years ago
- Example application for creating multiple desktops on Windows☆132Updated 6 years ago
- DLL Injection tool to unlock guest VMs☆232Updated 12 years ago
- Live hunting of code injection techniques☆380Updated 5 years ago
- Zerokit/GAPZ rootkit (non buildable and only for researching)☆180Updated 5 years ago
- A C/C++ implementation of Microsoft's Antimalware Scan Interface☆177Updated 6 years ago
- A list of ways to execute code on Windows using legitimate Windows tools☆304Updated 5 years ago
- Position Independent Windows Shellcode Written in C☆287Updated 6 years ago
- a tool to make it easy and fast to test various forms of injection☆172Updated 5 years ago
- Pazuzu: Reflective DLL to run binaries from memory☆213Updated 4 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆148Updated 5 years ago
- Bypassing User Account Control (UAC) using TpmInit.exe☆127Updated 8 years ago
- Enumerate Windows Defender threat families and dump their names according category☆88Updated 5 years ago
- Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process.☆156Updated 5 years ago
- A process overwriting its own PEB to make an illusion that it has been loaded from a different path.☆93Updated 3 years ago
- Windows Console Monitoring☆99Updated 7 years ago
- DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior☆271Updated 5 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆181Updated 7 years ago
- Remove individual lines from Windows XML Event Log (EVTX) files☆265Updated 3 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆99Updated 5 years ago
- ChimeraPE (a PE injector type - alternative to: RunPE, ReflectiveLoader, etc) - a template for manual loading of EXE, loading imports pay…☆219Updated last year
- Universal Unhooking☆318Updated 6 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- Mario & Luigi - Tools for sniffing Windows Named Pipes communication☆129Updated 8 years ago
- ☆213Updated 6 years ago
- ☆61Updated 4 years ago
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- Small tool to get a SYSTEM shell☆130Updated 9 years ago
- Documentation and supporting script sample for Windows Exploit Guard☆148Updated 3 years ago