x0reaxeax / PageSplit
Splitting and executing shellcode across multiple pages
☆99Updated last year
Related projects ⓘ
Alternatives and complementary repositories for PageSplit
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- Identify and exploit leaked handles for local privilege escalation.☆105Updated last year
- A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls☆104Updated 2 months ago
- ☆118Updated last year
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆164Updated last year
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆75Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- ☆133Updated last year
- ☆96Updated last year
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆55Updated 3 months ago
- ☆73Updated last year
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆113Updated last year
- ☆108Updated last year
- Find DLLs with RWX section☆75Updated last year
- Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space☆120Updated last year
- Create Anti-Copy DRM Malware☆46Updated 3 months ago
- Do some DLL SideLoading magic☆75Updated last year
- Template-based generation of shellcode loaders☆67Updated 7 months ago
- Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar☆117Updated 3 months ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated 9 months ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- It's pointy and it hurts!☆122Updated 2 years ago
- Simple BOF to read the protection level of a process☆104Updated last year
- ☆106Updated last year
- Malware?☆70Updated last month
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- ☆122Updated 11 months ago
- A tool for converting SysWhispers3 syscalls for use with Nim projects☆138Updated 2 years ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆73Updated last month