Three different shellcode techniques on the Windows Kernel
☆17Apr 8, 2025Updated last year
Alternatives and similar repositories for Windows-Kernel-Shellcode
Users that are interested in Windows-Kernel-Shellcode are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- kASLR bypass technique on Intel CPUs.☆34May 18, 2025Updated last year
- Various techniques used to bypass SMEP in the Windows Kernel.☆18Apr 20, 2025Updated last year
- Windows Kernel Security: Memory Integrity Verification with Disk Verification of ntoskrnl.exe☆28Mar 23, 2025Updated last year
- PE Sections Packer + Loader for Windows - Packs a DLL/EXE file and maps it into the loader (C/C++)☆15Oct 19, 2025Updated 9 months ago
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread☆33Sep 24, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repository to gather the BOF files I will be developing☆11Oct 1, 2024Updated last year
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆25Oct 30, 2024Updated last year
- Obfuscate payloads using IPv4, IPv6, MAC or UUID strings☆24Feb 17, 2024Updated 2 years ago
- .NET Project for performing Authenticated Remote Execution☆12Nov 22, 2023Updated 2 years ago
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆35Jan 17, 2026Updated 6 months ago
- Collection of different rootkit functionality, each driver representing a different rootkit component☆14May 27, 2025Updated last year
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆103Mar 20, 2023Updated 3 years ago
- Load Encrypted Dll Using LoadLibraryA, Keep The Dll Encrypted on disc all the time and decrypt it only in memory.☆24Sep 5, 2021Updated 4 years ago
- ACTIVELabs Security Advisories☆24May 19, 2021Updated 5 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- IAT-Obfuscation to make static analysis of executable harder.☆43Sep 6, 2021Updated 4 years ago
- ☆17Jan 14, 2026Updated 6 months ago
- ☆16Oct 31, 2021Updated 4 years ago
- Port of Mandiant ShellcodeHashes plugin from IDA to BinaryNinja☆11Jul 24, 2024Updated last year
- A tool that bypasses Windows Defender by manually loading DLLs, parsing EAT directly, and updating IAT with unhooked functions to run M…☆21Jul 14, 2024Updated 2 years ago
- 32 bit process inject shellcode to 32 bit process and 64 bit process☆35May 8, 2023Updated 3 years ago
- Proof of concepts demonstrating some aspects of the Windows kernel shadow stack mitigation.☆75Jun 2, 2025Updated last year
- Assembly code to use for Windows kernel shellcode to edit winlogon.exe ACL☆13Mar 6, 2017Updated 9 years ago
- Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-…☆16Jun 4, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Kernel Shellcode to add all privileges in token☆15Mar 13, 2017Updated 9 years ago
- Beacon Object File (BOF) Template☆95Mar 9, 2026Updated 4 months ago
- Config files for my GitHub profile.☆18Mar 21, 2026Updated 3 months ago
- Here you can find some vulnerable Windows Kernel Drivers☆13Feb 21, 2025Updated last year
- 针对windows rootkit的一些检测,分别从进程、端口、文件这三个方面进行检测。☆21Jan 16, 2025Updated last year
- Process injection alternative☆408Sep 6, 2024Updated last year
- x64 Registration-Free In-Process COM Automation Server.☆51Nov 28, 2022Updated 3 years ago
- 一款微信小程序源码包信息收集工具,根据已有项目改编☆24Feb 11, 2025Updated last year
- Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2☆13Jul 15, 2023Updated 3 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆39Apr 6, 2026Updated 3 months ago
- Minimal rust wrapper for Karabiner-DriverKit-VirtualHIDDevice☆16Jul 12, 2026Updated last week
- All my POC related to malware development☆15Feb 19, 2026Updated 5 months ago
- An injector that aims to be stealthy by using non suspicious API calls. Inspired by (https://github.com/FuzzySecurity/Sharp-Suite/tree/ma…☆24Jun 17, 2020Updated 6 years ago
- USB Monitor is a simple C# program that uses WMI to track information about newly connected and disconnected USB devices☆23Dec 16, 2023Updated 2 years ago
- AIDA64DRIVER Elevation of Privilege Vulnerability☆17Oct 25, 2024Updated last year
- ☆19May 1, 2026Updated 2 months ago