susMdT / SharpIndirectSyscalls
☆11Updated 2 years ago
Alternatives and similar repositories for SharpIndirectSyscalls:
Users that are interested in SharpIndirectSyscalls are comparing it to the libraries listed below
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- C# loader capable of running stage-1 from remote url, file path as well as file share☆17Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆70Updated last year
- ForsHops☆22Updated this week
- Example of using Sleep to create better named pipes.☆41Updated last year
- Hooked create process injection for meterpreter☆23Updated 3 years ago
- One gate to all syscalls!☆23Updated 3 years ago
- miscellaneous codes☆35Updated last year
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 2 years ago
- A work in progress BOF/COFF loader in Rust☆47Updated 2 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆25Updated last month
- Reimplementation of the KExecDD DSE bypass technique.☆47Updated 6 months ago
- API Hammering with C++20☆45Updated 2 years ago
- ☆25Updated 2 months ago
- ☆43Updated last year
- Extension functionality for the NightHawk operator client☆27Updated last year
- Halos Gate-based NTAPI Unhooker☆51Updated 2 years ago
- idk man this was the default github name☆35Updated last year
- Threadless injection via TLS callbacks☆16Updated 4 months ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆30Updated 9 months ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆59Updated last year
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be…☆19Updated last year
- This POC provides the possibilty to execute x86 shellcode in form of a .bin file based on x86 inline assembly☆18Updated last year
- My implementation of Halo's Gate technique in C#☆54Updated 2 years ago
- Evilbytecode-Gate resolves Windows System Service Numbers (SSNs) using two methods: analyzing the Guard CF Table in ntdll.dll and parsing…☆20Updated last month
- Proxy function calls through the thread pool with ease☆23Updated last month
- Modified Version of Melkor @FuzzySecurity capable of creating disposable AppDomains in injected processes.☆27Updated 3 years ago
- ☆20Updated 9 months ago
- ☆25Updated 3 months ago