rek7 / ddoorLinks
DDoor - cross platform backdoor using dns txt records
☆30Updated 4 years ago
Alternatives and similar repositories for ddoor
Users that are interested in ddoor are comparing it to the libraries listed below
Sorting:
- Executes shellcode from a remote server and aims to evade in-memory scanners☆32Updated 6 years ago
- An example of PE hollowing injection technique☆25Updated 6 years ago
- Injects shellcode into remote processes using direct syscalls☆77Updated 5 years ago
- ☆15Updated 5 years ago
- Collection of shellcode injection and execution techniques☆18Updated 5 months ago
- Offensive RPC PoC☆88Updated 4 years ago
- ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Ima…☆41Updated 2 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆41Updated 5 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 4 years ago
- Process Hollowing demonstration & explanation☆35Updated 4 years ago
- Windows (ShadowMove) Socket Duplication☆87Updated 5 years ago
- A small library helping to parse commandline parameters (for C/C++)☆58Updated 8 months ago
- ☆65Updated 3 years ago
- improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys☆49Updated 2 years ago
- CSharp Writeups for HackSys Extreme Vulnerable Driver☆45Updated 4 years ago
- Source files for my posts☆17Updated 2 years ago
- ☆14Updated 4 years ago
- ollvm, based on llvm-clang 5.0.2, 6.0.1, 7.0.1, 8.0, 9.0, 9.0.1☆19Updated 3 years ago
- Parser for a custom executable formats from Hidden Bee and Rhadamanthys malware☆58Updated 5 months ago
- ☆31Updated 5 years ago
- Cross-platform malware development library for anti-analysis techniques☆25Updated 4 years ago
- Example RPC service for blog post☆17Updated 6 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆79Updated 5 years ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆57Updated 3 years ago
- Reverse shell without Windows cmd.exe, using ReactOS cmd.dll as shellcode☆23Updated 5 years ago
- A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original…☆97Updated 6 years ago
- NT AUTHORITY\SYSTEM☆43Updated 5 years ago
- A small commented POC for removing API hooks placed by AV/EDR.☆34Updated 5 years ago
- ☆37Updated 4 years ago
- Bypass UAC by abusing the Internet Explorer Add-on installer☆57Updated 4 years ago