synacktiv / keebcap
Win32 keylogger that supports all (non-ime using) languages correctly
☆35Updated last year
Alternatives and similar repositories for keebcap:
Users that are interested in keebcap are comparing it to the libraries listed below
- Windows AppLocker Driver (appid.sys) LPE☆47Updated 5 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- ☆96Updated last year
- ☆83Updated 4 months ago
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆17Updated 8 months ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆43Updated 10 months ago
- stack spoofing☆74Updated 2 months ago
- A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.☆65Updated last month
- ☆109Updated 2 years ago
- ☆29Updated last month
- Template-based generation of shellcode loaders☆72Updated 8 months ago
- A more reliable way of resolving syscall numbers in Windows☆50Updated 11 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- ☆36Updated last year
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Free☆60Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Repo that holds random POCs☆48Updated last year
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- ☆29Updated last year
- ☆84Updated 7 months ago
- Reimplementation of the KExecDD DSE bypass technique.☆46Updated 4 months ago
- Exploiting the KsecDD Windows driver through Server Silos☆37Updated 2 months ago
- ☆42Updated last year
- based on https://gitlab.com/ORCA000/snaploader☆42Updated last month
- API Hammering with C++20☆43Updated 2 years ago
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆105Updated 4 months ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆41Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- Rusty Hell's Gate / Halo's Gate / Tartarus' Gate / FreshyCalls / Syswhispers2 Library☆25Updated 2 years ago