
Anti_suspend
Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

Shellcode-based process protection that prevents thread suspension, blocks debugger attach, masks hardware breakpoints, and hides threads from…

基于Java实现的Shellcode加载器

A shellcode function to encrypt a running process image when sleeping.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Various ways to execute shellcode

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

Nim Library for Offensive Security Development

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

Apply a divide and conquer approach to bypass EDRs

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

Shellcode Loader with Indirect Dynamic syscall Implementation , shellcode in MAC format, API resolving from PEB, Syscall calll and syscall…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)


Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".
