qwqdanchun / Malware-Note
https://docs.qwqdanchun.com/
☆27Updated 3 years ago
Alternatives and similar repositories for Malware-Note:
Users that are interested in Malware-Note are comparing it to the libraries listed below
- ☆39Updated last year
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆62Updated 2 years ago
- Indirect NT syscalls LSASS dumper.☆39Updated last year
- Change hash for a signed pe☆15Updated last year
- Evasive loader to bypass static detection☆56Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆68Updated last year
- My personal shellcode loader☆31Updated last year
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆43Updated last year
- Crossplatform tool for inject shellcode into .exe and .dll binaries (x86 and x64)☆57Updated 9 months ago
- Explorer Persistence technique : Hijacking cscapi.dll order loading path and writing our malicious dll into C:\Windows\cscapi.dll , when …☆81Updated 2 years ago
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆42Updated 9 months ago
- Windows shellcode encoding and encrypting tool☆21Updated 2 years ago
- ☆36Updated 2 years ago
- A Cobalt Strike memory evasion loader for redteamers☆97Updated 2 years ago
- A simple Sleepmask BOF example☆86Updated 5 months ago
- Windows C++ Implant for Exploration C2☆25Updated last week
- Beacon Debugger☆39Updated 3 months ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆100Updated last year
- A Flask-based HTTP(S) command and control (C2) framework with a web interface. Custom Windows EXE/DLL implants written in C++. For educat…☆88Updated last year
- ☆14Updated 2 years ago
- ☆63Updated last year
- This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built i…☆32Updated 3 years ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆62Updated last year
- This PoC uses two diferent technics for stealing the primary token from all running processes, showing that is possible to impersonate a…☆56Updated 3 years ago
- Hide Port In Windows☆38Updated 3 months ago
- ProcExp Driver (Ab)use☆20Updated 2 years ago
- Persistence via Shell Extensions☆64Updated last year
- replace the shellcode chatacters so that reduce the entropy☆16Updated last year
- MappingInjection via csharp☆38Updated 3 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆82Updated last year