Pinned Repositories
ApiHashing
Replacing GetModuleHandle & GetProcAddress as a God
AtomPePacker
A Highly capable Pe Packer
DeleteShadowCopies
Deleting Shadow Copies In Pure C++
EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events
GP
using the gpu to hide your payload
HellShell
transform your payload into ipv4/ipv6/mac arrays
KnownDllUnhook
Replace the .txt section of the current loaded modules from \KnownDlls\ to bypass edrs
NoRunPI
Run Your Payload Without Running Your Payload
Syscallslib
a library that automates some clean syscalls to make it easier to implement
TerraLdr
A Payload Loader Designed With Advanced Evasion Features
ORCx41's Repositories
ORCx41/AtomPePacker
A Highly capable Pe Packer
ORCx41/TerraLdr
A Payload Loader Designed With Advanced Evasion Features
ORCx41/KnownDllUnhook
Replace the .txt section of the current loaded modules from \KnownDlls\ to bypass edrs
ORCx41/NoRunPI
Run Your Payload Without Running Your Payload
ORCx41/ApiHashing
Replacing GetModuleHandle & GetProcAddress as a God
ORCx41/DeleteShadowCopies
Deleting Shadow Copies In Pure C++
ORCx41/EtwSessionHijacking
A Poc on blocking Procmon from monitoring network events
ORCx41/Syscallslib
a library that automates some clean syscalls to make it easier to implement
ORCx41/EntropyFix
reducing the entropy of your payload
ORCx41/W0wS3cur1tyEDR
a edr like program that hooks some syscalls
ORCx41/Ultra
A Small Poc On An Encryption/Decryption Algorithm Used As A File Locker
ORCx41/ManualRsrcDataFetching
Get your data from the resource section manually, with no need for windows apis
ORCx41/HellShell
transform your payload into ipv4/ipv6/mac arrays
ORCx41/D-R-Shellcode
download and run your payload from a url
ORCx41/GP
using the gpu to hide your payload
ORCx41/T.D.P.
Using Thread Description To Hide Shellcodes
ORCx41/KctHijackLib
using the kct to run your shellcode the apt style
ORCx41/RecycleBinPersistence
using the Recycle Bin to insure persistence
ORCx41/SnapLoader
just me playing with c
ORCx41/PerunsFart
replace and unhook ntdll from a suspended process
ORCx41/ToasterLoader
just a stupid way to run a payload
ORCx41/AsmLogger
asm keylogger that handles special characters and writes to a file
ORCx41/openbsd
Source code pulled from OpenBSD for LibreSSL - this includes most of the library and supporting code. The place to contribute to this code is via the OpenBSD CVS tree. Please mail patches to tech@openbsd.org, instead of submitting pull requests, since this tree is often rebased.
ORCx41/EDRs
ORCx41/Ekko
Sleep Obfuscation
ORCx41/FOLIAGE
Public variation of FOLIAGE ( original developer )
ORCx41/KaynLdr
KaynLdr is a Reflective Loader written in C/ASM
ORCx41/ORCx41
ORCx41/process_ghosting
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
ORCx41/VX-API
Collection of various malicious functionality to aid in malware development