trailofbits / RpcInvestigator
Exploring RPC interfaces on Windows
☆315Updated last year
Alternatives and similar repositories for RpcInvestigator:
Users that are interested in RpcInvestigator are comparing it to the libraries listed below
- C# Utilities for Windows Notification Facility☆128Updated 2 months ago
- RPC Monitor tool based on Event Tracing for Windows☆337Updated 5 months ago
- For when DLLMain is the only way☆365Updated 3 months ago
- Sysmon-Like research tool for ETW☆350Updated 2 years ago
- Dump the memory of any PPL with a Userland exploit chain☆332Updated last year
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆366Updated 3 months ago
- Aims to identify sleeping beacons☆562Updated 2 months ago
- Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting☆357Updated 2 years ago
- Tools and PoCs for Windows syscall investigation.☆357Updated last month
- ☆492Updated 3 months ago
- ☆214Updated 2 years ago
- Static Binary Instrumentation tool for Windows x64 executables☆196Updated last week
- ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Sysc…☆115Updated 5 months ago
- A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC☆352Updated 2 years ago
- Bring your own print driver privilege escalation tool☆247Updated 3 years ago
- MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.☆203Updated last year
- Leaked Windows processes handles identification tool☆282Updated 2 years ago
- FreshyCalls tries to make the use of syscalls comfortable and simple, without generating too much boilerplate and in modern C++17!☆321Updated 2 years ago
- Enumerating and removing kernel callbacks using signed vulnerable drivers☆548Updated 2 years ago
- Expriments☆452Updated 4 months ago
- Enumerate various traits from Windows processes as an aid to threat hunting☆186Updated 3 years ago
- ☆181Updated 2 years ago
- Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows☆203Updated 2 years ago
- miscellaneous scripts and programs☆232Updated 3 weeks ago
- Security product hook detection☆315Updated 3 years ago
- Yet another variant of Process Hollowing☆376Updated 3 weeks ago
- PoCs for Kernelmode rootkit techniques research.☆352Updated 3 weeks ago
- EDRSandblast-GodFault☆250Updated last year
- HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.☆650Updated last year
- TartarusGate, Bypassing EDRs☆561Updated 3 years ago