Use of in-memory string scans to outsmart reverse engineers
☆19Nov 20, 2024Updated last year
Alternatives and similar repositories for Memory-Mirage-Anti-Debugging-
Users that are interested in Memory-Mirage-Anti-Debugging- are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Shadow Rebirth - An Aggressive Outbreak Anti-Debugging Technique☆21Dec 3, 2024Updated last year
- Anti-Debugging (Self-Debugging)☆17Sep 6, 2025Updated 10 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 10 months ago
- use python on windows with full submodule support without installation☆30Jan 23, 2025Updated last year
- Early Bird Cryo Injections – APC-based DLL & Shellcode Injection via Pre-Frozen Job Objects☆145Apr 6, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jun 15, 2026Updated last month
- Rehashing APIs to prevent hash based detection☆14Jan 7, 2025Updated last year
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Library of BOFs to interact with SQL servers☆16Dec 6, 2024Updated last year
- Playing with packets in C#☆15Aug 16, 2024Updated last year
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆74Feb 17, 2026Updated 5 months ago
- Evasive shellcode loader with indirect syscalls, Thread name-calling allocation, PoolParty injection☆10Feb 26, 2025Updated last year
- Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared libra…☆87Nov 6, 2025Updated 8 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆42Aug 5, 2025Updated 11 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Shroudware is a compile-time obfuscation library implemented entirely in the C preprocessor.☆27Apr 12, 2026Updated 3 months ago
- Example of call stack spoofing trough the construction of syntetic frames and stack manipulation☆35Jan 17, 2026Updated 6 months ago
- DeadManSwitch in rust with several triggers (remote local and network)☆23Nov 19, 2025Updated 8 months ago
- ☆22Jun 24, 2025Updated last year
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆46Apr 6, 2025Updated last year
- AES-GEM (AES Galois Extended Mode) implementation.☆14May 19, 2026Updated 2 months ago
- Evasion kit for Cobalt Strike☆30Jan 16, 2026Updated 6 months ago
- Memory API proxy via signed mozglue.dll☆40Jun 25, 2026Updated 3 weeks ago
- Sample Rust crate used to implement a VBS enclave in Rust☆48Jun 3, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Anti Suspend and Detect Detaching from debuggers.☆17Apr 1, 2024Updated 2 years ago
- An ICMP channel for Beacons, implemented using Cobalt Strike’s External C2 framework.☆122Oct 6, 2025Updated 9 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.☆56Mar 30, 2026Updated 3 months ago
- Small external program that will attempt to detect and disable minhook hooks in a process☆25Dec 23, 2023Updated 2 years ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆120Dec 21, 2025Updated 6 months ago
- C# to read WIM files over the network without transferring the whole file☆40Jan 22, 2026Updated 5 months ago
- C2 Agent fully PIC for Mythic with advanced evasion capabilities, dotnet/powershell/shellcode/bof memory executions, lateral moviments, p…☆211Dec 30, 2025Updated 6 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆15Feb 16, 2026Updated 5 months ago
- Dll injection through code page id modification in registry. Based on jonas lykk research☆16Jun 18, 2022Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- executing shellcode directly from a python variable☆30Dec 20, 2025Updated 7 months ago
- Dumping processes using a kernel-mode driver.☆20Nov 10, 2021Updated 4 years ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆52Jun 7, 2023Updated 3 years ago
- Cross-platform CPU-based virtual machine detection framework for modern offensive security.☆48Feb 28, 2026Updated 4 months ago
- A Crystal Palace shared library to resolve & perform syscalls☆61Oct 29, 2025Updated 8 months ago
- PE Sections Packer + Loader for Windows - Packs a DLL/EXE file and maps it into the loader (C/C++)☆15Oct 19, 2025Updated 9 months ago
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆94Mar 29, 2026Updated 3 months ago