tux3 / crowdstrike-cloudprotoLinks
Async rust support for the reverse-engineered Crowdstrike Falcon protocol between the Sensor and cloud services
☆14Updated 2 years ago
Alternatives and similar repositories for crowdstrike-cloudproto
Users that are interested in crowdstrike-cloudproto are comparing it to the libraries listed below
Sorting:
- A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.☆30Updated 2 years ago
- ☆25Updated 2 years ago
- Windows kernel PDB data parsed into YAML☆39Updated 8 months ago
- ☆47Updated 3 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆30Updated 3 years ago
- Slides from various conference talks☆37Updated 2 years ago
- anti-ransomware file-system filter☆59Updated 10 months ago
- A Practical example of ELAM (Early Launch Anti-Malware)☆34Updated 3 years ago
- ☆21Updated 4 years ago
- C Header Only Library for Virii☆10Updated 4 years ago
- ☆14Updated last year
- Small tool to play with IOCs caused by Imageload events☆42Updated 2 years ago
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆21Updated last year
- An example of Windows self-replicating malware.☆11Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆32Updated last year
- Command line utility for copying files on NTFS using low level disk access☆36Updated last year
- really ?☆12Updated last year
- ☆71Updated 2 years ago
- Clone running process with ZwCreateProcess☆58Updated 4 years ago
- A few examples of how to trap virtual memory access on Windows.☆31Updated 7 months ago
- Repository of Microsoft Driver Block Lists based off of OS-builds☆39Updated last year
- SPI flash read MitM attack PoC☆38Updated 3 years ago
- Winbindex bot to pull in binaries for specific releases☆48Updated last year
- An example of COM hijacking using a proxy DLL.☆28Updated 3 years ago
- Small visualizator for PE files☆69Updated last year
- ☆25Updated 2 years ago
- SoulExtraction is a windows driver library for extracting cert information in windows drivers☆24Updated 2 years ago
- ☆25Updated last year
- Dangling COM Keys Finder☆17Updated 3 years ago
- run process as PPL Antimalware☆10Updated last year