t0-retooling / defender-recon24
☆38Updated last month
Related projects ⓘ
Alternatives and complementary repositories for defender-recon24
- Enabled / Disable LSA Protection via BYOVD☆62Updated 2 years ago
- ☆24Updated last year
- HEVD Exploit: BufferOverflowNonPagedPoolNx on Windows 10 22H2 - Escalating from Low Integrity to SYSTEM via Aligned Chunk Confusion☆39Updated 3 months ago
- ☆67Updated last year
- Monitors ETW for security relevant syscalls maintaining the set called by each unique process☆49Updated last year
- 64bit WIndows 10 shellcode dat pops dat calc - Dynamic & Null Free☆58Updated last year
- the Open Source and Pure C++ Packer for eXecutables☆18Updated last year
- Winbindex bot to pull in binaries for specific releases☆46Updated last year
- A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process☆87Updated 2 years ago
- ☆27Updated 4 months ago
- A PoC tool for exploiting leaked process and thread handles☆30Updated 9 months ago
- A (quite) simple steganography algorithm to hide shellcodes within bitmap image.☆21Updated 6 months ago
- A work in progress BOF/COFF loader in Rust☆45Updated last year
- ☆57Updated last year
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 4 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Standalone Metasploit-like XOR encoder for shellcode☆46Updated 6 months ago
- Analysis of the vulnerability☆47Updated 10 months ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆51Updated 2 years ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆42Updated 8 months ago
- PoC for the Untrusted Pointer Dereference in the appid.sys driver☆13Updated 7 months ago
- ☆58Updated 2 years ago
- defender_database☆17Updated last year
- Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE☆64Updated last year
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆45Updated last month
- Extracted lua script from Defender mpavbase.vdm and mpasbase.vdm☆12Updated 4 months ago
- C# implementation to produce ROR-13 numeric hash for given function API name☆31Updated 5 years ago