nybble04 / Shady-HookLinks
Proof of Concept - Hooking API calls of a Ransomware
☆28Updated 4 years ago
Alternatives and similar repositories for Shady-Hook
Users that are interested in Shady-Hook are comparing it to the libraries listed below
Sorting:
- Windows kernel PDB data parsed into YAML☆36Updated 6 months ago
- A ready-made template for a project based on libpeconv.☆48Updated 3 months ago
- ☆22Updated 4 years ago
- Sysmon shenanigans☆65Updated 4 years ago
- A small library helping to parse commandline parameters (for C/C++)☆57Updated last week
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 4 years ago
- Bare template for a Kernel Mode Driver☆51Updated 5 years ago
- Gozi ISFB is a well-known and widely distributed banking trojan, and has been in the threat landscape for the past several years.☆64Updated 7 years ago
- ☆71Updated last year
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- DLL Injection Library & Tools☆72Updated 8 years ago
- PoC designed to evade userland-hooking anti-virus.☆88Updated 6 years ago
- Parsers for custom malware formats ("Funky malware formats")☆96Updated 3 years ago
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- PoC for detecting and dumping process hollowing code injection☆51Updated 6 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆75Updated 6 years ago
- Windows Drivers☆98Updated 6 years ago
- Driver Initial Reconnaissance Tool☆123Updated 5 years ago
- ☆36Updated 6 years ago
- Ebfuscator: Abusing system errors for binary obfuscation☆52Updated 5 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆35Updated 9 years ago
- DotNext 2019 St. Petersburg Talk Demos☆40Updated 6 years ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆108Updated 4 years ago
- Evil Reflective DLL Injection Finder☆47Updated 6 years ago
- Simple Process Hollowing in C#☆69Updated 7 years ago
- ☆61Updated last year
- Small visualizator for PE files☆69Updated last year
- ☆21Updated 5 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆43Updated 8 months ago
- Code that can be used as a reference, library, or inspiration for hacking Windows memory.☆50Updated 5 years ago