therealdreg / okhi
Open Keylogger Hardware Implant - USB & PS2 Keyboards
☆56Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for okhi
- FTDI bricker just for fun - malware POC+hardware hacking CTF☆18Updated 2 months ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- RunPE adapted for x64 and written in C, does not use RWX☆24Updated 6 months ago
- Reimplementation of the KExecDD DSE bypass technique.☆42Updated 2 months ago
- Attack chain emulator. Write recipes for initial access easily☆20Updated last year
- Section-based payload obfuscation technique for x64☆58Updated 3 months ago
- Splitting and executing shellcode across multiple pages☆99Updated last year
- ☆58Updated 11 months ago
- Collect Windows telemetry for Maldev☆62Updated this week
- EvtPsst☆54Updated last year
- A class to emulate the behavior of NtQuerySystemInformation when passed the SystemHypervisorDetailInformation information class☆24Updated last year
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆104Updated 2 months ago
- ☆27Updated last year
- A attempt at replicating BLACKLOTUS capabilities, whilst not acting as a direct mimic.☆85Updated last year
- A Mythic Agent written in PIC C.☆92Updated this week
- A more reliable way of resolving syscall numbers in Windows☆49Updated 9 months ago
- A pure C version of SymProcAddress☆23Updated 8 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆38Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 4 months ago
- Piece of code to detect and remove hooks in IAT☆58Updated 2 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- Plantronics Desktop Hub LPE☆36Updated 6 months ago
- Sample Rust Hooking Engine☆34Updated 7 months ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated 11 months ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆43Updated 6 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆63Updated 2 months ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- a stage1 DLL loader with sleep obfuscation☆32Updated last year
- ☆81Updated 3 months ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆80Updated 9 months ago