ulexec / SHELF-Loading
Evasive ELF Static PIE User-Land-Exec featured in Tmpout Vol 1.
☆25Updated 3 years ago
Alternatives and similar repositories for SHELF-Loading:
Users that are interested in SHELF-Loading are comparing it to the libraries listed below
- PoC multi-layer protector for ELF32 x86 binaries☆10Updated 2 years ago
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆28Updated 11 months ago
- ☆16Updated 3 years ago
- An injector that use PT_LOAD technique☆12Updated 2 years ago
- ☆27Updated 5 years ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆29Updated last year
- ☆46Updated 2 years ago
- Extract data of TTD trace file to a minidump☆28Updated last year
- ☆12Updated 2 years ago
- Poc for ELF64 runtime infection via GOT poisoning technique by elfmaster☆29Updated 4 years ago
- ELF Virus infection techniques that work with SCOP (Secure code partitioned) executables☆14Updated 5 years ago
- ☆12Updated 3 years ago
- Finds imports that could be exploited, still requires manual analysis.☆27Updated 2 years ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- Non organized Cpp code files I used for my research on Windows☆18Updated 4 years ago
- DoublePulsar (Position-Independent) Shellcode (Windows 7 SP1 x64)☆26Updated 4 years ago
- ☆22Updated last year
- ☆12Updated last year
- reboot of https://github.com/Genetic-Malware/Ebowla in order to simplify / modernize the codebase and provide ongoing support☆22Updated 3 years ago
- ☆24Updated 3 years ago
- This is a simple tool to dump all the reparse points on an NTFS volume.☆31Updated 4 years ago
- Repository for Flare-On challenges and solutions/code☆9Updated 2 months ago
- ☆11Updated 5 years ago
- ☆20Updated 5 years ago
- PoC of macho loading from memory☆53Updated 2 months ago
- A simple tool to view important DLL Characteristics and change DEP and ASLR☆44Updated 6 years ago
- ☆18Updated last year
- ☆14Updated 3 years ago
- Load a dynamic library from memory using a fuse mount☆30Updated last year
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 4 years ago