Handle access elevation via direct kernel object manipulation
☆118Jan 26, 2018Updated 8 years ago
Alternatives and similar repositories for ElevateMe
Users that are interested in ElevateMe are comparing it to the libraries listed below
Sorting:
- x64 manualmapper with kernel elevation and thread hijacking capabilities☆418Jan 3, 2020Updated 6 years ago
- ☆14Jan 10, 2017Updated 9 years ago
- ☆57Nov 14, 2017Updated 8 years ago
- Undocumented way of fetching list of processes by bruteforcing NtQuerySystemInformation☆16Nov 20, 2017Updated 8 years ago
- Common Malware Techniques☆13Mar 26, 2023Updated 2 years ago
- Tool that dumps beacon frames to a pcap file. Works on Windows Vista or Later with any Wireless Card.☆27Mar 19, 2022Updated 3 years ago
- An usermode alternative for DuplicateHandle.☆177Aug 12, 2017Updated 8 years ago
- Securing Data Analytics on Intel SGX using Randomization☆13Aug 30, 2017Updated 8 years ago
- analyze the content of the pe file on windows, and shell(pack) function for windows drivers.☆11Nov 9, 2018Updated 7 years ago
- NT reversal☆25Jul 12, 2018Updated 7 years ago
- Dll injector POC for new handle stealing technique☆21Oct 8, 2017Updated 8 years ago
- NoBastian - Universal Ring3 IPC based BattlEye/EAC/FaceIt/ESEA/MRAC bypass☆147Jun 17, 2018Updated 7 years ago
- Windows handle stealing POC with NtDuplicateObject☆41May 7, 2017Updated 8 years ago
- WIP - Play with Intel VM Extensions☆23Jun 12, 2017Updated 8 years ago
- Obtain remote process cookies by performing a brute-force attack on ntdll.RtlDecodePointer using known pointer encodings.☆22May 31, 2017Updated 8 years ago
- an efficient yet easy to use network packet builder and parser☆11Jul 3, 2017Updated 8 years ago
- An usermode BE Rootkit Bypass☆240May 1, 2019Updated 6 years ago
- Bypass User Account Control by manipulating tokens☆35Nov 3, 2017Updated 8 years ago
- x64 usermode rootkit☆211Apr 11, 2018Updated 7 years ago
- anti-virtualmachine with C!☆23Apr 10, 2016Updated 9 years ago
- ☆11Jun 15, 2017Updated 8 years ago
- Open-Source Anti-RMT-Spam Firewall☆12Mar 28, 2016Updated 9 years ago
- Windows hidden thread suspend POC with code injection☆12May 27, 2017Updated 8 years ago
- Detect manualmapped images remotely, without hassle☆152Nov 3, 2017Updated 8 years ago
- ☆60Mar 4, 2019Updated 6 years ago
- ShellcodeVM☆15Jun 20, 2016Updated 9 years ago
- Detect the SCI in windows.☆11Mar 23, 2017Updated 8 years ago
- ☆11Sep 28, 2017Updated 8 years ago
- ☆13Jun 20, 2013Updated 12 years ago
- This DKOM exploit enables any app in usermode to access physical memory directly☆228Nov 24, 2017Updated 8 years ago
- BattlEye x64 usermode injector☆66Mar 20, 2019Updated 6 years ago
- Class implementation of PowerLoader injection technique☆32Dec 23, 2016Updated 9 years ago
- ☆24Nov 17, 2017Updated 8 years ago
- An analytical debugger programmed in C++, using Qt.☆22May 20, 2012Updated 13 years ago
- midfunction d3d basehook for winxp, win7, win8, win10☆17Jan 21, 2019Updated 7 years ago
- League Sandbox's Replay Inspector☆12Sep 6, 2018Updated 7 years ago
- The Network project is a C++ encapsulation of WinSock2 to form a lightweight network library; The Graphics project is a C++ encapsulation…☆13Oct 31, 2017Updated 8 years ago
- ☆27Oct 16, 2017Updated 8 years ago
- Notes my learning steps about Windows-NT☆23May 18, 2017Updated 8 years ago