whokilleddb / function-collectionsLinks
A collection of PoCs to do common things in unconventional ways
☆122Updated 4 months ago
Alternatives and similar repositories for function-collections
Users that are interested in function-collections are comparing it to the libraries listed below
Sorting:
- Linker for Beacon Object Files☆146Updated this week
- Shellcode loader☆98Updated last year
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆136Updated 4 months ago
- "Service-less" driver loading☆165Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆83Updated last year
- PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin☆102Updated 2 weeks ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆118Updated 3 weeks ago
- A collection of position independent coding resources☆106Updated 2 months ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆116Updated last year
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆136Updated last year
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆202Updated 4 months ago
- ForsHops☆59Updated 9 months ago
- Windows User-Mode Shellcode Development Framework (WUMSDF)☆120Updated 2 months ago
- ☆86Updated 11 months ago
- ☆108Updated last year
- Activation Context Hijack☆169Updated 5 months ago
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆180Updated 2 months ago
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆103Updated 10 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆137Updated 4 months ago
- load shellcode without P/D Invoke and VirtualProtect call.☆164Updated 4 months ago
- ☆159Updated last year
- Code execution/injection technique using DLL PEB module structure manipulation☆220Updated 7 months ago
- Threadless shellcode injection tool☆67Updated last year
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆135Updated 9 months ago
- Fairy Law - Compromise or disable EDR security solutions☆65Updated last month
- Bypass LSA protection using the BYODLL technique☆170Updated last year
- shell code example☆67Updated last month
- Locate dlls and function addresses without PEB Walk and EAT parsing☆97Updated 2 months ago
- ☆126Updated last year
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆256Updated 3 months ago