timwhitez / memmodLinks
Fork & modify of Wireguard's Memmod
☆32Updated last year
Alternatives and similar repositories for memmod
Users that are interested in memmod are comparing it to the libraries listed below
Sorting:
- load assembly executable file in memory☆41Updated last year
- Its a coff loader ported to go( Modified by TimWhite )☆27Updated last year
- ☆30Updated 2 years ago
- Golang implementation of Hellsgate + Halosgate/Tartarosgate. Ensures that all systemcalls go through ntdll.dll;☆32Updated 3 years ago
- Code with Windows Hacker☆13Updated 2 years ago
- ☆41Updated last year
- Bypass EDR Create TaskServers☆37Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆49Updated 2 years ago
- ☆24Updated 2 months ago
- ☆46Updated last year
- Beacon Object File implementation of pwn1sher's KillDefender☆66Updated 3 years ago
- (Hellsgate|Halosgate|Tartarosgate)+Spoofing-Gate. Ensures that all systemcalls go through ntdll.dll☆43Updated 3 years ago
- BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel☆27Updated last year
- AddDefenderExclusions Beacon Object File☆39Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that uses LogonUserSSPI API to perform kerberos-based password spray☆47Updated 2 years ago
- desktop screenshot☆30Updated 2 years ago
- Golang implement winrm client with pass the hash☆31Updated last year
- dump lsass☆37Updated 3 years ago
- dump lsass tool☆39Updated 2 years ago
- query specific user and login IP from remote machine☆17Updated 2 years ago
- Learning notes of amazing Sliver C2 project.☆25Updated 2 years ago
- Re-implement cmd.exe using windows api☆49Updated 2 years ago
- Load CLR to get RWX 通过加载clr在自身内存中产生rwx空间☆22Updated 2 years ago
- use aswArPot.sys to kill process☆68Updated 2 years ago
- ☆19Updated 2 years ago
- MSSQL CLR for pentest.☆54Updated last year
- command execute without 445 port☆52Updated 3 years ago
- Delete file regardless of whether the handle is used via SetFileInformationByHandle☆44Updated 2 years ago
- CVE-2023-21707 EXP☆28Updated 2 years ago
- Automatically parse Malleable C2 profiled into CrossC2 rebinding library source code☆21Updated 2 years ago