synacktiv / keebcap
Win32 keylogger that supports all (non-ime using) languages correctly
☆44Updated last year
Alternatives and similar repositories for keebcap:
Users that are interested in keebcap are comparing it to the libraries listed below
- ☆60Updated 8 months ago
- Template-based generation of shellcode loaders☆73Updated 10 months ago
- Exploiting the KsecDD Windows driver through Server Silos☆50Updated 3 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆70Updated last month
- ☆84Updated 6 months ago
- API Hammering with C++20☆45Updated 2 years ago
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆125Updated 6 months ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆64Updated this week
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆17Updated 9 months ago
- ☆97Updated last year
- XOR decrypting shellcode using the GPU with OpenCL.☆93Updated last year
- ☆134Updated last year
- ☆112Updated 2 years ago
- stack spoofing☆80Updated 3 months ago
- ☆93Updated last month
- ☆36Updated 2 years ago
- Splitting and executing shellcode across multiple pages☆99Updated last year
- early cascade injection PoC based on Outflanks blog post, in rust☆53Updated 3 months ago
- Activation cache poisoning to elevate from medium to high integrity (CVE-2024-6769)☆61Updated 4 months ago
- Rusty Hell's Gate / Halo's Gate / Tartarus' Gate / FreshyCalls / Syswhispers2 Library☆26Updated 2 years ago
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆54Updated last month
- Files for http://blog.deniable.org/posts/windows-callbacks/☆69Updated 2 years ago
- a modified CONTEXT based ropchain to circumvent CFG-FindHiddenShellcode and EtwTi-FluctuationMonitor☆93Updated 10 months ago
- Malware?☆69Updated 4 months ago
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆122Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆70Updated last year
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆58Updated last year
- ☆51Updated last month