sbousseaden / injection-1
Windows process injection methods
☆14Updated 5 years ago
Alternatives and similar repositories for injection-1:
Users that are interested in injection-1 are comparing it to the libraries listed below
- APC DLL Injector with NtQueueApcThread and wake up thread support☆45Updated 7 years ago
- A simple dumper as FreshyCalls' PoC. That's what's trendy, isn't it? ¯\_(ツ)_/¯☆39Updated 4 years ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- A tool to create COM class/interface relationships in neo4j☆47Updated 2 years ago
- Recreating and reviewing the Windows persistence methods☆37Updated 3 years ago
- ☆31Updated 4 years ago
- ☆36Updated 3 years ago
- ☆37Updated 3 years ago
- ☆69Updated last year
- ☆59Updated 2 years ago
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆53Updated 2 years ago
- A PoC tool for exploiting leaked process and thread handles☆30Updated 11 months ago
- A small commented POC for removing API hooks placed by AV/EDR.☆33Updated 4 years ago
- A simple PE loader.☆25Updated 2 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- A C port of b33f's UrbanBishop☆38Updated 4 years ago
- Windows API Hashes used in the malwares☆40Updated 9 years ago
- Self Delete DLL☆23Updated 11 months ago
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆70Updated last year
- Resolve syscall numbers at runtime for all Windows versions.☆60Updated 2 months ago
- ☆15Updated 4 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- An example of COM hijacking using a proxy DLL.☆25Updated 3 years ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆24Updated 3 years ago
- Loads .NET Assembly Via CLR Loader☆15Updated 5 years ago
- A simple COM server which provides a component to run shellcode☆132Updated 4 years ago
- A novel technique to communicate between threads using the standard ETHREAD structure☆111Updated 3 years ago
- Sysmon shenanigans☆66Updated 4 years ago
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆25Updated last year