p0dalirius / microsoft-rpc-fuzzing-tools
This repository contains a list of python scripts to work with Microsoft RPC for research purposes.
☆45Updated last month
Alternatives and similar repositories for microsoft-rpc-fuzzing-tools:
Users that are interested in microsoft-rpc-fuzzing-tools are comparing it to the libraries listed below
- ☆79Updated 11 months ago
- A simple C++ Windows tool to get information about processes exposing named pipes.☆36Updated 2 weeks ago
- BYOVD collection☆23Updated last year
- ☆82Updated 3 years ago
- PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy☆35Updated last year
- ☆28Updated 10 months ago
- ☆88Updated 2 years ago
- A work in progress BOF/COFF loader in Rust☆47Updated 2 years ago
- remote process injections using pool party techniques☆55Updated last month
- Analysis of the vulnerability☆50Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆101Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.☆15Updated 2 years ago
- Plantronics Desktop Hub LPE☆37Updated 10 months ago
- ☆26Updated 2 years ago
- ☆39Updated 2 years ago
- Beacon Object Files (not Buffer Overflows)☆53Updated 2 years ago
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- Arbitrary File Delete in Windows Installer before 10.0.19045.2193☆29Updated 2 years ago
- Identify and exploit leaked handles for local privilege escalation.☆106Updated last year
- Execute dotnet app from unmanaged process☆71Updated 2 months ago
- ☆53Updated last year
- ☆98Updated last year
- ☆108Updated 4 months ago
- ☆62Updated 2 years ago
- Sliver agent rewritten in C++☆44Updated 6 months ago
- Slides from out talk at BH IL 2022☆28Updated 3 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆83Updated 2 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆72Updated 2 months ago