zodiacon / sysrun
Run any executable as SYSTEM account (no service required)
☆119Updated 4 months ago
Related projects: ⓘ
- Log ALPC activity☆80Updated 11 months ago
- Explore Job Objects on a Windows system☆79Updated 5 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆84Updated 8 years ago
- Demo service that runs in svchost.exe☆79Updated 6 years ago
- API Set Viewer☆83Updated 4 years ago
- Used to create wrappers and proxy libraries for Windows binaries.☆69Updated 12 years ago
- Authenticode Hash Calculator for PE32/PE32+ files☆104Updated 6 months ago
- Process Doppelgänging☆152Updated 6 years ago
- View handles and object for each object type☆61Updated 5 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆129Updated 5 years ago
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 3 years ago
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆153Updated 6 months ago
- Reflective PE loader for DLL injection☆167Updated 6 years ago
- Shellcode to load an appended Dll☆89Updated 3 years ago
- Assembly block for hooking windows API functions.☆81Updated 5 years ago
- An command-line RPC method enumerator, born out of RPCView's awesomeness☆97Updated 5 years ago
- Execute commands as local system.☆61Updated 5 years ago
- C++ library for low-level Windows development☆69Updated 5 months ago
- This is a sample that shows how to leverage SetThreadContext for DLL injection☆79Updated 7 years ago
- PoC designed to evade userland-hooking anti-virus.☆85Updated 5 years ago
- ☆110Updated this week
- Convert PE files to a shellcode☆73Updated 4 years ago
- A PoC designed to bypass all usermode hooks in a WoW64 environment.☆147Updated 4 years ago
- Trace events in real time sessions☆42Updated last year
- Weaponizing Gigabyte driver for priv escalation and bypass PPL☆68Updated 5 years ago
- Kernel Pool Monitor☆118Updated 2 years ago
- ☆88Updated 3 years ago
- ☆179Updated 2 years ago
- An example of a client and server using Windows' ALPC functions to send and receive data.☆88Updated 4 years ago
- A simple POC to demonstrate the power of .NET debugging for injection☆71Updated 4 years ago