
windows-api-function-cheatsheets
A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

different ntdll unhooking techniques : unhooking ntdll from disk, from KnownDlls, from suspended process, from remote server (fileless)

Port of Cobalt Strike's Process Inject Kit

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Fileless x64 Assembly C2 framework with dual-channel ICMP/DNS protocol pivoting, direct syscall execution, and ptrace-based process injection for…

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

How to spoof the command line when spawning a new process from C#.

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…

Remove API hooks from a Beacon process.

Runtime process analysis and memory hacking MCP server for AI agents. Supports dynamic extension loading, read-only mode, audit logging, and…

Lightweight library which allows the ability to map both native and managed assemblies into memory by either using process injection of a process…

Windows process injection methods

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

# VortexCry-Ransomware VortexCry is an advanced ransomware that utilizes multi-stage process injection (such as Process Hollowing and APC Injection)…

A collection of samples and material related to process injection

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…