zodiacon / sysrun
Run any executable as SYSTEM account (no service required)
☆125Updated 8 months ago
Alternatives and similar repositories for sysrun:
Users that are interested in sysrun are comparing it to the libraries listed below
- Log ALPC activity☆79Updated last year
- Authenticode Hash Calculator for PE32/PE32+ files☆108Updated 10 months ago
- Explore Job Objects on a Windows system☆81Updated 5 years ago
- API Set Viewer☆84Updated 5 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆85Updated 9 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆50Updated 4 years ago
- View handles and object for each object type☆63Updated 5 years ago
- Used to create wrappers and proxy libraries for Windows binaries.☆73Updated 13 years ago
- Shellcode to load an appended Dll☆89Updated 4 years ago
- Trace events in real time sessions☆44Updated last year
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆100Updated 5 years ago
- C++ library for low-level Windows development☆72Updated 9 months ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆139Updated 5 years ago
- Reflective PE loader for DLL injection☆171Updated 7 years ago
- Process Doppelgänging☆155Updated 7 years ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆163Updated 10 months ago
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- An example of how x64 kernel shellcode can dynamically find and use APIs☆104Updated 4 years ago
- Assembly block for hooking windows API functions.☆81Updated 5 years ago
- A driver that hooks C: volume using symbolic link callback to track all FS access to the volume☆103Updated 4 years ago
- ☆69Updated last year
- ☆79Updated 3 years ago
- Samples from my book Windows Native API programming☆59Updated 5 months ago
- A PoC designed to bypass all usermode hooks in a WoW64 environment.☆148Updated 4 years ago
- Run Processes as PPL with ELAM☆154Updated 2 years ago
- Command like tool to print mitigation flags for running processes in a memory dump☆47Updated 4 years ago
- ☆190Updated 2 years ago
- Demo service that runs in svchost.exe☆79Updated 7 years ago
- Execute commands as local system.☆63Updated 5 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆56Updated 6 years ago