synacktiv / DLHellLinks
Local & remote Windows DLL Proxying
☆169Updated last year
Alternatives and similar repositories for DLHell
Users that are interested in DLHell are comparing it to the libraries listed below
Sorting:
- ☆159Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆147Updated 2 years ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆194Updated last year
- Your syscall factory☆126Updated 2 weeks ago
- A BOF to enumerate system process, their protection levels, and more.☆123Updated last year
- A hoontr must hoont☆102Updated 3 weeks ago
- SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the proce…☆152Updated 4 months ago
- Simple BOF to read the protection level of a process☆119Updated 2 years ago
- WTSImpersonator utilizes WTSQueryUserToken to steal user tokens by abusing the RPC Named Pipe "\\pipe\LSM_API_service"☆121Updated last year
- Stage 0☆167Updated last year
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆185Updated last year
- Remotely Enumerate sessions using undocumented Windows Station APIs☆118Updated last year
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Updated 8 months ago
- Port of Cobalt Strike's Process Inject Kit☆189Updated last year
- EDR-Redir : a tool used to redirect the EDR's folder to another location.☆210Updated last month
- Create Anti-Copy DRM Malware☆69Updated last year
- Find DLLs with RWX section☆80Updated 2 years ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆181Updated 9 months ago
- ☆151Updated 2 years ago
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆141Updated 3 weeks ago
- A Mythic agent for Windows written in C☆142Updated this week
- ☆122Updated 2 years ago
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆149Updated last year
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year
- ☆137Updated 10 months ago
- ☆115Updated last year
- Find .net assemblies locally☆128Updated 3 years ago
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆195Updated 10 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆122Updated last year
- The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section☆108Updated 2 years ago