volexity / donut-decryptorLinks
Retrieve inner payloads from Donut samples
☆102Updated last year
Alternatives and similar repositories for donut-decryptor
Users that are interested in donut-decryptor are comparing it to the libraries listed below
Sorting:
- Windows Persistence IT-Security☆102Updated 4 months ago
- ☆119Updated last year
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆103Updated 3 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆129Updated 3 weeks ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated 11 months ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆89Updated last year
- .NET tool used to enrich RPC telemetry☆87Updated last month
- IoctlHunter is a command-line tool designed to simplify the analysis of IOCTL calls made by userland software targeting Windows drivers.☆103Updated last year
- SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the proce…☆132Updated 8 months ago
- Local & remote Windows DLL Proxying☆165Updated last year
- ☆86Updated last year
- ☆107Updated 8 months ago
- Detect EDR's exceptions by inspecting processes' loaded modules☆130Updated last year
- Identifies bad bytes from static analysis with any Anti-Virus scanner.☆124Updated last year
- ☆155Updated 7 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆120Updated last year
- A BOF to enumerate system process, their protection levels, and more.☆117Updated 7 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆188Updated 7 months ago
- Find DLLs with RWX section☆81Updated 2 years ago
- Finding secrets in kernel and user memory☆116Updated last year
- I have documented all of the AMSI patches that I learned till now☆73Updated 3 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆206Updated 6 months ago
- ☆105Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆81Updated 10 months ago
- ☆78Updated last year
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆147Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆76Updated last year
- Early Bird APC Injection in Rust☆58Updated 9 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year