
KsDumper
Dumping processes using the power of kernel space !

Dumping processes using the power of kernel space !

A pure-Python library that lets you inspect, modify and search the memory of any running process in a few lines of Python :snake: .

Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a…

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

This program is designed to demonstrate various process injection techniques

A memory-based evasion technique which makes shellcode invisible from process start to end.

Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)