
Christmas
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

PoC demonstrating a multi process injection chain aimed at remotely executing shellcode

Windows memory hacking library

A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management,…

This program is designed to demonstrate various process injection techniques

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

PoCs and tools for investigation of Windows process execution techniques

Dump cookies and credentials directly from Chrome/Edge process memory

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird + Spawns a…

A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

some gadgets about windows process and ready to use :)

Credentials gathering tool automating remote procdump and parse of lsass process.

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

This is the tool to dump the LSASS process on modern Windows 11