Highlights
- Pro
Lists (1)
Sort Name ascending (A-Z)
Starred repositories
Header-only TOML config file parser and serializer for C++17.
Windows Local Privilege Escalation from Service Account to System
Load self-signed drivers without TestSigning or disable DSE. Transferred from https://github.com/DoubleLabyrinth/Windows10-CustomKernelSigners
Extract and execute a PE embedded within a PNG file using an LNK file.
Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
Tools and packages that are used for countering forensic activities, including encryption, steganography, and anything that modify attributes. This all includes tools to work with anything in gener…
Driver that uses network sockets to communicate with client and read/ write protected process memory.
An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution
Hook system calls, context switches, page faults and more.
Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!
Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...
tiny, portable SOCKS5 server with very moderate resource usage
Bypassing UAC with SSPI Datagram Contexts
This project aims to compare and evaluate the telemetry of various EDR products.
The Grimoire Hypervisor solution for x86 Processors with experimental nested virtualization support.
Example of waiting for Event Objects by associating them with a I/O Completion Port (IOCP), effectively lifting MAXIMUM_WAIT_OBJECTS (64) limit of WaitForMultipleObjects(Ex) API.
Identify common EDR processes, directories, and services. Simple BOF of Invoke-EDRChecker.
nsync is a C library that exports various synchronization primitives, such as mutexes
A high-performance tun2socks for Linux/Android/FreeBSD/macOS/iOS/WSL2 (IPv4/IPv6/TCP/UDP)
Lateral Movement Using DCOM and DLL Hijacking
整合Pluto-Obfuscator和goron部分混淆,移植到LLVM-16.0.x,使用NewPassManager