stormshield / HiveSwarmingLinks
Convert .reg to registry hive and reciprocally, without elevation
☆79Updated 9 months ago
Alternatives and similar repositories for HiveSwarming
Users that are interested in HiveSwarming are comparing it to the libraries listed below
Sorting:
- PS-MOTW: PowerShell scripts to set / show / remove MOTW (Mark of the Web)☆54Updated 2 years ago
- ☆31Updated last year
- Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2☆51Updated 2 years ago
- ☆108Updated last year
- List the ETW provider(s) in the registration table of a process.☆80Updated 2 years ago
- a tiny program to consume from ETW providers for research☆53Updated last year
- ☆79Updated last year
- Just another ntdll unhooking using Parun's Fart technique☆76Updated 2 years ago
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆74Updated 2 weeks ago
- A collection of PoCs to do common things in unconventional ways☆122Updated 5 months ago
- A lightweight Windows Prefetch file parser to extract programs' execution history☆62Updated 3 weeks ago
- Identifies LOLDrivers that are not blocked by the active HVCI policy — ideal for BYOVD scenarios.☆75Updated 6 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- Commandline spoofing on Windows☆92Updated 2 months ago
- ☆38Updated 9 months ago
- .NET tool used to enrich RPC telemetry☆101Updated 2 weeks ago
- "Service-less" driver loading☆177Updated last year
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Updated 9 months ago
- Remap ntdll.dll using only NTAPI functions with a suspended process☆27Updated 9 months ago
- Win32 keylogger that supports all (non-ime using) languages correctly☆53Updated 2 years ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆119Updated last month
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆115Updated last year
- Read ETW Provider events. Inspired by ETWExplorer by Pavel Yosifovich☆17Updated last year
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆81Updated 7 months ago
- Test AMSI Provider implementation in C#☆42Updated last year
- Blog/Journal on how to backdoor VSCode extensions☆76Updated 6 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆140Updated 2 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆62Updated last year
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆92Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year