An example of using Syscalls in C# to get a meterpreter shell.
☆113Oct 7, 2021Updated 4 years ago
Alternatives and similar repositories for Sys-Calls
Users that are interested in Sys-Calls are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An example of using Dynamic Invoke to Inject Shellcode using the Early Bird Method.☆15Dec 14, 2023Updated 2 years ago
- Another meterpreter injection technique using C# that attempts to bypass Defender☆265Oct 20, 2021Updated 4 years ago
- C# version of MDSec's ParallelSyscalls☆144Jan 9, 2022Updated 4 years ago
- A collection of C# shellcode injection techniques. All techniques use an AES encrypted meterpreter payload. I will be building this proje…☆466Oct 22, 2021Updated 4 years ago
- Simple PoC demonstrating syscall execution in C#☆160Apr 30, 2020Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Execute shellcode with ZwCreateSection, ZwMapViewOfSection, ZwOpenProcess, ZwMapViewOfSection and ZwCreateThreadEx☆15Apr 26, 2021Updated 5 years ago
- Another AMSI bypass - but in C++.☆22May 22, 2023Updated 3 years ago
- Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.☆16Jan 21, 2022Updated 4 years ago
- A custom run space to bypass AMSI and Constrained Language mode in PowerShell.☆20May 17, 2023Updated 3 years ago
- Dynamically invoke arbitrary unmanaged code from managed code without P/Invoke.☆170Jan 25, 2024Updated 2 years ago
- C# code to Sandbox Defender (and most probably other AV/EDRs).☆166Apr 22, 2022Updated 4 years ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆112Apr 14, 2023Updated 3 years ago
- Small POC for process ghosting☆39Feb 1, 2022Updated 4 years ago
- C# Reflective loader for unmanaged binaries.☆447Jan 25, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆16Nov 23, 2021Updated 4 years ago
- ☆79Feb 13, 2024Updated 2 years ago
- C# Based Universal API Unhooker☆408Feb 18, 2022Updated 4 years ago
- The repository that complements the From zero to hero: creating a reflective loader in C# workshop☆40Oct 6, 2021Updated 4 years ago
- Loads any C# binary in mem, patching AMSI + ETW.☆850Oct 3, 2021Updated 4 years ago
- A simple shell code encryptor/decryptor/executor to bypass anti virus.☆467Dec 13, 2021Updated 4 years ago
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆297Jul 15, 2023Updated 3 years ago
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆87Jun 24, 2022Updated 4 years ago
- KaynLdr is a Reflective Loader written in C/ASM☆554Dec 3, 2023Updated 2 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Generate Shellcode Loaders & Injects☆160May 15, 2023Updated 3 years ago
- Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!☆450Mar 8, 2023Updated 3 years ago
- Remotely dump NT hashes through Windows Crash dumps☆34Apr 23, 2026Updated 2 months ago
- Replace the .txt section of the current loaded modules from \KnownDlls\☆307Sep 28, 2022Updated 3 years ago
- Patch AMSI and ETW☆252May 8, 2024Updated 2 years ago
- Hookers are cooler than patches.☆170Jan 21, 2022Updated 4 years ago
- C# Lsass parser☆297Oct 13, 2021Updated 4 years ago
- Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll☆511Feb 3, 2022Updated 4 years ago
- Porting of BOF InlineExecute-Assembly to load .NET assembly in process but with patchless AMSI and ETW bypass using hardware breakpoint.☆298Jun 12, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆15Feb 9, 2022Updated 4 years ago
- ☆1,702Apr 14, 2025Updated last year
- How to spoof the command line when spawning a new process from C#.☆112Dec 28, 2021Updated 4 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆36Apr 5, 2022Updated 4 years ago
- PoC for UUID shellcode execution using DInvoke☆157Mar 8, 2021Updated 5 years ago
- ☆143Jun 21, 2023Updated 3 years ago
- all credits go to @mgeeky☆65Oct 14, 2021Updated 4 years ago