zodiacon / sysrun
Run any executable as SYSTEM account (no service required)
☆127Updated 10 months ago
Alternatives and similar repositories for sysrun:
Users that are interested in sysrun are comparing it to the libraries listed below
- Log ALPC activity☆82Updated last year
- View handles and object for each object type☆62Updated 5 years ago
- Explore Job Objects on a Windows system☆82Updated 5 years ago
- Process Doppelgänging☆156Updated 7 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆87Updated 9 years ago
- Shellcode to load an appended Dll☆88Updated 4 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆139Updated 6 years ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆94Updated 2 months ago
- Authenticode Hash Calculator for PE32/PE32+ files☆109Updated last year
- API Set Viewer☆88Updated 2 months ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Demo service that runs in svchost.exe☆79Updated 7 years ago
- Reflective PE loader for DLL injection☆174Updated 7 years ago
- C++ library for low-level Windows development☆72Updated 11 months ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆169Updated last year
- A PoC designed to bypass all usermode hooks in a WoW64 environment.☆149Updated 4 years ago
- Kernel Pool Monitor☆122Updated 3 years ago
- Yet another PE Viewer☆139Updated 2 years ago
- A WinDbg extension to trace COM interactions☆114Updated last year
- ☆191Updated 2 years ago
- Assembly block for hooking windows API functions.☆87Updated 5 years ago
- Convert PE files to a shellcode☆74Updated 4 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆103Updated 5 years ago
- An example of how x64 kernel shellcode can dynamically find and use APIs☆104Updated 4 years ago
- APC Internals Research Code☆162Updated 4 years ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆209Updated 5 years ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- c++ implementation of windows heavens gate☆68Updated 4 years ago
- Reverse engineered source code of the autochk rootkit☆201Updated 5 years ago
- NINA: No Injection, No Allocation x64 Process Injection Technique☆195Updated 4 years ago