tehstoni / RustyKeys
UAC Bypass using CMSTP in Rust
☆26Updated 5 months ago
Alternatives and similar repositories for RustyKeys:
Users that are interested in RustyKeys are comparing it to the libraries listed below
- Cortex EDR Ransomware protection Bypass☆21Updated 3 months ago
- Tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆37Updated 7 months ago
- an Improoved Version of 0xNinjaCyclone´s EarlyCascade Code☆19Updated 2 months ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆29Updated 3 months ago
- Windows Thread Pool Injection Havoc Implementation☆29Updated last year
- Hunting and injecting RWX 'mockingjay' DLLs in pure nim☆59Updated 5 months ago
- ☆55Updated 6 months ago
- T-1 is a shellcode loader that leverages ML techniques to detect VM environments☆25Updated 6 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆58Updated 6 months ago
- The Swiss army knife of evasion tool that bypasses AMSI, Applocker, and CLM mode simultaneously.☆27Updated last year
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆76Updated 2 months ago
- 「⚠️」Performing a BYOVD on the truesight.sys driver☆34Updated 5 months ago
- Windows Active DIrectory Pentesting documentation.☆18Updated 10 months ago
- BOF for C2 framework☆41Updated 6 months ago
- Research into WinSxS binaries and finding hijackable paths☆28Updated 2 weeks ago
- Enable or Disable TokenPrivilege(s)☆13Updated 11 months ago
- ☆22Updated 2 months ago
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆39Updated 6 months ago
- Impersonate Tokens using only NTAPI functions☆71Updated last month
- Section-based payload obfuscation technique for x64☆59Updated 9 months ago
- Lifetime AMSI bypass.☆34Updated 2 weeks ago
- ☆105Updated 6 months ago
- Just another ntdll unhooking using Parun's Fart technique☆75Updated 2 years ago
- A collection of position independent coding resources☆78Updated 2 months ago
- ☆50Updated 6 months ago
- BOF to decrypt Signal Desktop chat logs☆65Updated 2 months ago
- POC of GITHUB simple C2 in rust☆53Updated 3 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 9 months ago
- A pure C version of SymProcAddress☆27Updated last year