
Archived
Modules
Modules used by the Havoc Framework
authenticationcommand-and-controlinformation-gathering+5

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

find dll base addresses without PEB WALK

A BOF designed to inspect processes memory and addresses