xpn / RpcEnum
An command-line RPC method enumerator, born out of RPCView's awesomeness
☆100Updated 5 years ago
Alternatives and similar repositories for RpcEnum:
Users that are interested in RpcEnum are comparing it to the libraries listed below
- Command like tool to print mitigation flags for running processes in a memory dump☆47Updated 4 years ago
- ☆69Updated last year
- Designed to learn OS specific anti-emulation patterns by fuzzing the Windows API.☆96Updated 4 years ago
- ☆79Updated 3 years ago
- An example of how x64 kernel shellcode can dynamically find and use APIs☆104Updated 4 years ago
- Weaponizing for Arbitrary Files/Directories Delete bugs to Get NT AUTHORITY\SYSTEM☆121Updated 4 years ago
- PoC demonstrating the use of cve-2020-1034 for privilege escalation☆120Updated 3 years ago
- ☆68Updated 2 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- Proof of concept exploit of Windows Update Orchestrator Service Elevation of Privilege Vulnerability☆121Updated 4 years ago
- Windows API Hashes used in the malwares☆40Updated 9 years ago
- Sysmon shenanigans☆66Updated 4 years ago
- ☆36Updated 3 years ago
- Helper idapython code for reversing kmdf drivers☆71Updated 2 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- Inter-Process Communication Mechanisms☆26Updated 4 years ago
- A simple COM server which provides a component to run shellcode☆132Updated 4 years ago
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆104Updated 4 years ago
- ☆50Updated 4 years ago
- Example code for EDR bypassing☆149Updated 5 years ago
- Hijack Printconfig.dll to execute shellcode☆97Updated 4 years ago
- Proxy system calls over an RPC channel☆96Updated 2 years ago
- APC DLL Injector with NtQueueApcThread and wake up thread support☆45Updated 7 years ago
- Inject unsigned DLL into Protected Process Light (PPL)☆19Updated last month
- A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original…☆93Updated 5 years ago
- ☆12Updated 4 years ago
- Assembly block for hooking windows API functions.☆81Updated 5 years ago