rek7 / ddoor
DDoor - cross platform backdoor using dns txt records
☆30Updated 3 years ago
Alternatives and similar repositories for ddoor:
Users that are interested in ddoor are comparing it to the libraries listed below
- Reverse Windows shell over TLS☆18Updated 9 years ago
- Executes shellcode from a remote server and aims to evade in-memory scanners☆31Updated 5 years ago
- Windows NTLM Authentication Backdoor☆14Updated 3 years ago
- Bypass UAC by abusing the Windows Defender Firewall Control Panel, environment variables, and shell protocol handlers☆18Updated 3 years ago
- improving zerosums smbdoor - a silent remote backdoor which abuses undoc. APIs in srvnet.sys☆49Updated last year
- x86 and x86-64 shellcodes for Windows, Mac OSX, Linux, BSD and Solaris☆15Updated 7 years ago
- Reverse shell without Windows cmd.exe, using ReactOS cmd.dll as shellcode☆22Updated 4 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆74Updated 5 years ago
- A simple injector that uses LoadLibraryA☆17Updated 4 years ago
- C# implementation of Shellcode delivery techniques using PInvoke and DInvoke variations for API calling.☆35Updated 3 years ago
- PE file mapping and manipulation package.☆36Updated 2 years ago
- (Sim)ulate (Ba)zar Loader☆29Updated 4 years ago
- NT AUTHORITY\SYSTEM☆38Updated 4 years ago
- Injects shellcode into remote processes using direct syscalls☆74Updated 4 years ago
- the Open Source and Pure C++ Packer for eXecutables☆18Updated last year
- ☆31Updated 4 years ago
- A crappy hook on SpAcceptLsaModeContext that prints incoming auth attempts. WIP☆33Updated 3 years ago
- A PoC to demo modifying cmdline of the child process dynamically. It might be useful against process log tracing, AV or EDR.☆38Updated 4 years ago
- ☆15Updated 4 years ago
- ollvm, based on llvm-clang 5.0.2, 6.0.1, 7.0.1, 8.0, 9.0, 9.0.1☆19Updated 2 years ago
- DLL Injector as a service that watches the health of the started thread.☆9Updated 5 years ago
- Recreating and reviewing the Windows persistence methods☆37Updated 3 years ago
- A reduced functionality cli client for the imdisk ram disk driver. To be used through a backdoor like meterpreter☆22Updated 6 years ago
- 64bit Windows 10 shellcode that adds user BOKU:SP3C1ALM0V3 to the system and the localgroups Administrators & "Remote Desktop Users"☆38Updated 3 years ago
- A simple PE loader.☆26Updated 2 years ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆54Updated 2 years ago
- Assembly API block that uses CRC32 for resolving Windows API function addresses☆18Updated last year
- Yet another Windows DLL injector.☆38Updated 3 years ago
- A local LKM rootkit loader/dropper that lists available security mechanisms☆52Updated 3 years ago
- PoC for DEF CON 26: Playing Malware Injection with Exploit thoughts☆23Updated 6 years ago