patrickmatula / Windows-Internals-Learning-ResourcesLinks
☆100Updated 7 months ago
Alternatives and similar repositories for Windows-Internals-Learning-Resources
Users that are interested in Windows-Internals-Learning-Resources are comparing it to the libraries listed below
Sorting:
- ☆107Updated 7 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 11 months ago
- ☆169Updated 2 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆112Updated 9 months ago
- Recon 2023 slides and code☆79Updated 2 years ago
- "Service-less" driver loading☆155Updated 6 months ago
- ☆133Updated 3 months ago
- Analyse MSI files for vulnerabilities☆137Updated 9 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆135Updated last year
- A collection of small scripts and tools for deobfuscation and malware analysis.☆66Updated 2 years ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- early cascade injection PoC based on Outflanks blog post☆219Updated 7 months ago
- ☆155Updated 6 months ago
- ☆119Updated last year
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆314Updated last year
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆78Updated this week
- ☆67Updated 4 months ago
- ☆124Updated 2 weeks ago
- SRE - Dissecting Malware for Static Analysis & the Complete Command-line Tool☆53Updated 5 months ago
- ☆105Updated 11 months ago
- Injecting DLL into LSASS at boot☆123Updated last month
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆205Updated 6 months ago
- Admin to Kernel code execution using the KSecDD driver☆251Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆64Updated last month
- Aplos an extremely simple fuzzer for Windows binaries.☆69Updated 4 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆88Updated this week
- Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider☆176Updated 2 years ago
- PowerShell PE Parser☆63Updated 11 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆110Updated last month