stavinski / winhook
Go library to allow native inline hooking in windows at runtime
☆13Updated last year
Alternatives and similar repositories for winhook:
Users that are interested in winhook are comparing it to the libraries listed below
- Shellcode reflective DLL injection in Rust☆19Updated last year
- My nim learning experiments☆11Updated 2 years ago
- Golang Implementation of Hell's gate☆17Updated last year
- ☆36Updated 10 months ago
- Load and execute a common object file format (COFF) in the current process☆28Updated last year
- A proof-of-concept created for academic/learning purposes, demonstrating both local and remote use of VSTO "Add-In's" maliciously☆31Updated 2 years ago
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- BYOVD collection☆23Updated last year
- Executes shellcode from a remote server and aims to evade in-memory scanners☆31Updated 5 years ago
- ☆19Updated last year
- Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)☆23Updated 3 years ago
- Simple HTTP async comms using standard GET/POST requests☆32Updated last month
- Ntdll Unhooking POC☆19Updated 2 years ago
- ☆18Updated 6 months ago
- Remap ntdll.dll using only NTAPI functions with a suspended process☆20Updated last week
- powershell script i wrote that can suspend an arbitrary process (with limits)☆20Updated 2 years ago
- ☆12Updated 2 years ago
- Find kernel32 base and API addresses. Simple C++ implementation☆24Updated 3 years ago
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆41Updated last year
- A .NET implementation to dump SAM, SYSTEM, SECURITY registry hives from a remote host☆39Updated last year
- A simple rpc2socks alternative in pure Go.☆28Updated 9 months ago
- A simple Linux in-memory .so loader☆30Updated 2 years ago
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies☆32Updated 2 years ago
- Windows C++ Implant for Exploration C2☆29Updated last month
- ☆18Updated 4 months ago
- A simple ExternalC2 POC for Havoc C2. Communicates over Notion using a custom python agent, handler and extc2 channel. Not operationally …☆85Updated 2 years ago
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆31Updated last year
- A work in progress BOF/COFF loader in Rust☆46Updated 2 years ago
- ☆48Updated 3 years ago
- Right-To-Left Override POC☆34Updated 3 years ago