tccontre / Reg-Restore-Persistence-Mole

a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Callback of sysmon driver filter. RegSaveKeyExW() and RegRestoreKeyW() API which is not included in monitoring. This POC will use
51Updated last year

Alternatives and similar repositories for Reg-Restore-Persistence-Mole:

Users that are interested in Reg-Restore-Persistence-Mole are comparing it to the libraries listed below