shantanu561993 / DLL-Sideload
☆38Updated last year
Related projects ⓘ
Alternatives and complementary repositories for DLL-Sideload
- Beacon Object Files (not Buffer Overflows)☆51Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆38Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Artemis - C++ Hell's Gate Syscall Implementation☆30Updated last year
- ☆61Updated 2 years ago
- ☆34Updated last year
- This is my own implementation of the Perun's Fart technique by Sektor7☆66Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- ☆51Updated last year
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆82Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- ☆39Updated 10 months ago
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- TypeLib persistence technique☆75Updated last month
- Quick python script to replace the NtAPI functions within SysWhispers' assembly and header files with random strings☆24Updated 2 years ago
- Tool for playing with Windows Access Token manipulation.☆52Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆88Updated 10 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆58Updated 8 months ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆53Updated 2 years ago
- ☆58Updated 2 years ago
- ☆38Updated last year
- Click Once + App Domain☆62Updated 11 months ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆51Updated last year
- ☆62Updated 9 months ago
- Sleep Obfuscation☆41Updated 2 years ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago