realoriginal / titanldr-ng
A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge years ago.
☆163Updated last year
Related projects ⓘ
Alternatives and complementary repositories for titanldr-ng
- ☆108Updated last year
- ☆133Updated last year
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- Single stub direct and indirect syscalling with runtime SSN resolving for windows.☆127Updated 2 years ago
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆113Updated last year
- TypeLib persistence technique☆73Updated 3 weeks ago
- Malware?☆70Updated last month
- ☆118Updated last year
- ☆117Updated 2 months ago
- Simple BOF to read the protection level of a process☆104Updated last year
- ☆96Updated last year
- Implant drop-in for EDR testing☆128Updated last year
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆118Updated 3 months ago
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆103Updated 2 months ago
- ☆119Updated last year
- An App Domain Manager Injection DLL PoC on steroids☆161Updated 11 months ago
- ☆59Updated 5 months ago
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Bypass LSA protection using the BYODLL technique☆146Updated 2 months ago
- Load a dynamic library from memory by modifying the native Windows loader☆204Updated last year
- Tool for playing with Windows Access Token manipulation.☆51Updated last year
- BOF combination of KillDefender and Backstab☆156Updated last year
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (…☆165Updated last year
- ☆106Updated last year
- Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctype…☆108Updated last year
- Cobalt Strike (CS) Beacon Object File (BOF) for kernel exploitation using AMD's Ryzen Master Driver (version 17).☆132Updated last year
- Use hardware breakpoints to spoof the call stack for both syscalls and API calls☆181Updated 5 months ago
- ☆133Updated last year