x0reaxeax / SysCook64
Indirect Syscall invocation via thread hijacking
☆13Updated last year
Related projects ⓘ
Alternatives and complementary repositories for SysCook64
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated 11 months ago
- Simple PoC to locate hooked functions by EDR in ntdll.dll☆32Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆39Updated 11 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆58Updated 8 months ago
- Sleep Obfuscation☆41Updated 2 years ago
- Threadless shellcode injection tool☆61Updated 3 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- a stage1 DLL loader with sleep obfuscation☆32Updated last year
- Reimplementation of the KExecDD DSE bypass technique.☆42Updated 2 months ago
- ☆34Updated last year
- Threadless injection via TLS callbacks☆15Updated this week
- TypeLib persistence technique☆75Updated last month
- DLL Hijacking and Mock directories technique to bypass Windows UAC security feature and getting high-level privileged reverse shell. Secu…☆37Updated 6 months ago
- A proof of concept I developed to improve Gargoyle back in 2018 to achieve true memory obfuscation from position independent code☆39Updated 2 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆37Updated 2 months ago
- This program is used to perform reflective DLL Injection to a remote process specified by the user.☆62Updated last year
- 🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python☆41Updated 8 months ago
- Patch AMSI and ETW in remote process via direct syscall☆77Updated 2 years ago
- Halos Gate-based NTAPI Unhooker☆49Updated 2 years ago
- stack spoofing☆53Updated this week