cr-0w's Stars
hasherezade/malware_training_vol1
Materials for Windows Malware Analysis training (volume 1)
hasherezade/process_doppelganging
My implementation of enSilo's Process Doppelganging (PE injection technique)
forrest-orr/ExploitDev
Various tools, PoCs and experiments related to my blog at https://www.forrest-orr.net/
yardenshafir/IoRingReadWritePrimitive
Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2
riskydissonance/SyscallsExample
Simple project using syscalls (via Syswhispers2) to execute MessageBox shellcode.
forrest-orr/phantom-dll-hollower-poc
Phantom DLL hollowing PoC
mgeeky/ShellcodeFluctuation
An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents
mgeeky/ThreadStackSpoofer
Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.
janoglezcampos/FindItByCalls
Hacky code for extracting calls in DLLs by function
grassmunk/Chicago95
A rendition of everyone's favorite 1995 Microsoft operating system for Linux.
kahlon81/Process-Injection-Direct-Syscall
Classic Process Injection but with direct syscalls
BlackArch/blackarch
An ArchLinux based distribution for penetration testers and security researchers.
elddy/Windows-NTAPI-Injector
Inject shellcode to process using Windows NTAPI for bypassing EDRs and Antiviruses
Maldev-Academy/EntropyReducer
Reduce Entropy And Obfuscate Youre Payload With Serialized Linked Lists
OpenSecurityResearch/dllinjector
dll injection tool that implements various methods
hzphreak/VMInjector
DLL Injection tool to unlock guest VMs
TCM-Course-Resources/Open-Source-Intellingence-Resources
Compilation of Resources from TCM's OSINT Course
Maldev-Academy/HellHall
Performing Indirect Clean Syscalls
NUL0x4C/AtomLdr
A DLL loader with advanced evasive features
0x00Check/ExploitLeakedHandle
Identify and exploit leaked handles for local privilege escalation.
x0reaxeax/lambda
it really is a lambda
SecuraBV/Timeroast
Timeroasting scripts by Tom Tervoort
x0reaxeax/Fetch-n-Exec
An x64 binary executing code that's not inside of it.
x0reaxeax/exec-prot-bypass
Bypassing Linux Executable Space Protection using 20+ years old tools (CVE-2022-25265).
x0reaxeax/rwlazer64
Win64 UEFI Driver-based tool for unrestricted memory R/W
Idov31/Cronos
PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.
the-xentropy/xencrypt
A PowerShell script anti-virus evasion tool
j00ru/windows-syscalls
Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)
dafthack/MailSniper
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
dafthack/MFASweep
A tool for checking if MFA is enabled on multiple Microsoft Services