thecatenjoyer / singlestep_xorstub
Stub for polymorphic code
☆12Updated 2 years ago
Alternatives and similar repositories for singlestep_xorstub:
Users that are interested in singlestep_xorstub are comparing it to the libraries listed below
- A few examples of how to trap virtual memory access on Windows.☆28Updated 3 months ago
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆18Updated 3 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- Grab Firefox post requests by hooking PR_Write function from nss3.dll module using trampoline hook to get passwords and emails of users☆42Updated 2 years ago
- Linux Sleep Obfuscation☆94Updated last year
- Attack chain emulator. Write recipes for initial access easily☆20Updated last month
- ☆12Updated last year
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- API Hammering with C++20☆45Updated 2 years ago
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 2 years ago
- Proof of Concept example for abusing Process Hacker 2 (v2.39.124)☆21Updated 5 months ago
- In-memory hiding technique☆47Updated 2 months ago
- really ?☆12Updated last year
- Persistence techniques for windows.☆19Updated last year
- A more reliable way of resolving syscall numbers in Windows☆48Updated last year
- Run payload like a Lazarus Group (UuidFromStringA). C++ implementation☆19Updated 2 years ago
- Callstack spoofing using a VEH because VEH all the things.☆19Updated last week
- Splitting and executing shellcode across multiple pages☆100Updated last year
- Released alongside with a talk at REcon 2023, TheRestarter is an interactive command-line tool is designed to interact with the Windows …☆14Updated last year
- ☆26Updated 2 years ago
- rust clr heap encryption (https://github.com/lap1nou/CLR_Heap_encryption), but no heap encryption.☆15Updated last year
- Native Powers Talk demos☆14Updated last year
- ELF Beacon Object File (BOF) Template☆18Updated 4 months ago
- Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver☆50Updated last year
- ☆20Updated 3 weeks ago
- ☆29Updated 3 months ago
- A small example of loading BOFs in Python with pure reflection☆19Updated 2 years ago
- A lexer and parser for Sleep☆16Updated 2 months ago
- ☆10Updated 2 years ago
- some AV / EDR / analysis studies☆11Updated last year