realoriginal / foliage
A proof of concept I developed to improve Gargoyle back in 2018 to achieve true memory obfuscation from position independent code
☆39Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for foliage
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆164Updated last year
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆127Updated 2 years ago
- Experiment on reproducing Obfuscate & Sleep☆139Updated 3 years ago
- ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption☆78Updated last year
- ☆106Updated last year
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- ☆133Updated last year
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆108Updated last year
- Collect Windows telemetry for Maldev☆57Updated this week
- Files for http://blog.deniable.org/posts/windows-callbacks/☆67Updated 2 years ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space