rad9800 / BloatedHammer
API Hammering with C++20
☆44Updated 2 years ago
Alternatives and similar repositories for BloatedHammer:
Users that are interested in BloatedHammer are comparing it to the libraries listed below
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆45Updated 4 months ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated 11 months ago
- Get your data from the resource section manually, with no need for windows apis☆56Updated 3 months ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆41Updated last year
- Splitting and executing shellcode across multiple pages☆99Updated last year
- Sleep Obfuscation☆43Updated 2 years ago
- ☆36Updated last year
- Patch AMSI and ETW in remote process via direct syscall☆80Updated 2 years ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆36Updated last year
- I have documented all of the AMSI patches that I learned till now☆69Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆98Updated last year
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- A method to execute shellcode using RegisterWaitForInputIdle API.☆52Updated last year
- A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.☆66Updated 2 months ago
- stack spoofing☆77Updated 2 months ago
- ☆96Updated last year
- ☆29Updated last month
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆44Updated 3 years ago
- Template-based generation of shellcode loaders☆72Updated 9 months ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆122Updated 2 years ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆172Updated last year
- lsassdump via RtlCreateProcessReflection and NanoDump☆77Updated 3 months ago
- ☆43Updated last week
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆60Updated last year