Pinned Repositories
AppContainerSandbox
An example sandbox using AppContainer (Windows 8+)
BasicHook
x86 Inline hooking engine (using trampolines)
CitrixHoneypot
Detect and log CVE-2019-19781 scan and exploitation attempts.
CreateDesktop
Example application for creating multiple desktops on Windows
EDR-Preloader
An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
EDRception
A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.
FakeMBR
TDL4 style rootkit to spoof read/write requests to master boot record
TinyXPB
Windows XP 32-Bit Bootkit
TrickBot-Toolkit
A collection of tools for dealing with TrickBot
ZombifyProcess
Inject code into a legitimate process
MalwareTech's Repositories
MalwareTech/EDR-Preloader
An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer
MalwareTech/TrickBot-Toolkit
A collection of tools for dealing with TrickBot
MalwareTech/EDRception
A proof of concept for abusing exception handlers to hook and bypass user mode EDR hooks.
MalwareTech/TinyXPB
Windows XP 32-Bit Bootkit
MalwareTech/ZombifyProcess
Inject code into a legitimate process
MalwareTech/AppContainerSandbox
An example sandbox using AppContainer (Windows 8+)
MalwareTech/CreateDesktop
Example application for creating multiple desktops on Windows
MalwareTech/FakeMBR
TDL4 style rootkit to spoof read/write requests to master boot record
MalwareTech/CitrixHoneypot
Detect and log CVE-2019-19781 scan and exploitation attempts.
MalwareTech/BasicHook
x86 Inline hooking engine (using trampolines)
MalwareTech/Log4jTools
Tools for investigating Log4j CVE-2021-44228
MalwareTech/HiddenDesktop
Create and enumerate hidden desktops.
MalwareTech/UACElevator
Passive UAC elevation using dll infection
MalwareTech/FstHook
A library for intercepting native functions by hooking KiFastSystemCall
MalwareTech/RDGScanner
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
MalwareTech/Beginner-Reversing-Challenges
https://www.malwaretech.com/beginner-malware-reversing-challenges
MalwareTech/CVE-2024-47176-Scanner
A simple scanner for identifying vulnerable cups-browsed instances on your network
MalwareTech/SpookySSLTools
Example tools for detecting software using OpenSSL 3.0.0 - 3.0.6 (vulnerable to latest unnamed vulnerability)
MalwareTech/MSDIA-x64
Enable Microsoft PDB support in Ghidra without installing Visual Studio
MalwareTech/FollinaExtractor
Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files
MalwareTech/SimpleEpollServer
An example epoll imlementation with C++11
MalwareTech/PhaseHack
Phase C&C Blind SQL Injection
MalwareTech/NeutrinoBotHack
SQL injection in Neutrino panel
MalwareTech/PhaseDump
Python tool for decrypting W32/Phase modules