Pinned Repositories
Atom_bombing
Commented version of Atom_bombing injection technique. Original source code from https://blog.ensilo.com/atombombing-brand-new-code-injection-for-windows
Carberp
Carberp Banking Trojan
CreateProcess
A simple C++ app to demo the use of CreateProcess() ,WaitForSingleObject() and use of handles.
DanSpecial
Weaponizing Gigabyte driver for priv escalation and bypass PPL
DrvMon
Advanced driver monitoring utility.
FileTest
Source code for File Test - Interactive File System Test Tool
malware-source-nanomites
NtCreateUserProcess_
peta909's Repositories
peta909/NtCreateUserProcess_
peta909/Atom_bombing
Commented version of Atom_bombing injection technique. Original source code from https://blog.ensilo.com/atombombing-brand-new-code-injection-for-windows
peta909/Processing_listing_CreateToolhelp32Snapshot
peta909/AndrewSpecial
AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.
peta909/Antimalware-Research
Research on Anti-malware and other related security solutions
peta909/aplib-ripper
Use this library to automatically extract PE files compressed with aplib from a binary blob.
peta909/BMI_Calulator
BMI Calculator use to demo used of passed by reference.
peta909/Class_OOP_CheatSheet
peta909/emofishes
Emofishes is a collection of proof of concepts that help improve, bypass or detect virtualized execution environments (focusing on the ones setup for malware analysis).
peta909/Files-Store
peta909/FindProcessUsingName
peta909/fuckVmp3
fuck like title.
peta909/HexRaysCodeXplorer
Hex-Rays Decompiler plugin for better code navigation
peta909/injection-1
Windows process injection methods
peta909/ksm
A fast, hackable and simple x64 VT-x hypervisor for Windows and Linux. Builtin userspace sandbox and introspection engine.
peta909/Mastering-Reverse-Engineering
Mastering Reverse Engineering, published by Packt
peta909/Native_NtSuspendProcess
Use NtSuspendProcess to suspend process
peta909/PE-Runtime-Data-Structures
peta909/pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
peta909/Pointers_References
peta909/Portable-Executable-PE-Format-Poster
A Portable Executable (PE) Format poster in A1 59,4 x 84,1 cm format, including almost all of the structures from PE/PE32+ format (with comments from WinNT.h header file).
peta909/Resonance
A C polymorphic and metamorphic engine
peta909/ScyllaHide
Advanced usermode anti-anti-debugger
peta909/sgxrop
The code to the SGX-ROP paper
peta909/shellerate
A shellcode generator with encryption, encoding and polymorphism facilities built-in
peta909/Wait4SingleObj_EX_QueueAPC
peta909/Win-LocalPriv-Escalation-polarbear
Windows Local Privilege Escalation - 0 Day Vulnerability (schtasks.exe) released by @SandboxEscaper :)
peta909/windbg-scripts
A bunch of JavaScript extensions for WinDbg.
peta909/youtube-dl
Command-line program to download videos from YouTube.com and other video sites
peta909/zerokit