zimnyaa / fiber-stager
A simple Nim stager (w/ fiber execution)
☆16Updated 3 years ago
Alternatives and similar repositories for fiber-stager:
Users that are interested in fiber-stager are comparing it to the libraries listed below
- Another AMSI bypass - but in C++.☆23Updated last year
- Unused DLL hollowing PoC in Nim☆17Updated 3 years ago
- A nim port of C5pider's Ekko project.☆18Updated 2 years ago
- Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts☆20Updated last year
- Resolve WinAPI func. Custom GetProcAddress and GetModuleHandle written in Nim☆33Updated 3 years ago
- A small example of loading BOFs in Python with pure reflection☆19Updated 2 years ago
- PoC XLL builder in Python/Nim☆45Updated 2 years ago
- Run python from a single exe☆35Updated 2 years ago
- ☆48Updated last year
- A repository filled with ideas to break/detect direct syscall techniques☆27Updated 2 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆12Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- RunPE adapted for x64 and written in C, does not use RWX☆24Updated 10 months ago
- Load and execute a common object file format (COFF) in the current process☆28Updated last year
- A lexer and parser for Sleep☆16Updated 2 months ago
- Hooked create process injection for meterpreter☆23Updated 3 years ago
- Extension functionality for the NightHawk operator client☆27Updated last year
- Remove API hooks from a Beacon process.☆13Updated 3 years ago
- Cobalt Strike notifications via NTFY.☆13Updated 6 months ago
- An example of COM hijacking using a proxy DLL.☆28Updated 3 years ago
- ☆28Updated 4 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆25Updated last month
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies☆32Updated 2 years ago
- API Hammering with C++20☆45Updated 2 years ago
- These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be…☆19Updated last year
- Self Delete DLL☆23Updated last year
- BOF for C2 framework☆40Updated 4 months ago
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆20Updated last year
- A simple Linux in-memory .so loader☆29Updated last year