Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
TangledWinExec — PoC e strumenti per l'analisi delle tecniche di esecuzione dei processi di Windows | Kitploit
Strumenti/GitHubGitHub/daem0nc0re/tangledwinexec
Evasione IDS/IPSReverse EngineeringShellcodeDebuggerPost-ExploitRed TeamingGenerazione di ShellcodeSviluppo PayloadAttacco Avversario
GitHubdaem0nc0re/tangledwinexec

TangledWinExec

PoC e strumenti per l'analisi delle tecniche di esecuzione dei processi di Windows

958147317 mesi faRevisionato da Kitploit
Vedi Repository

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Tangled WinExec

Questo repository è dedicato allo studio delle tecniche di esecuzione dei processi Windows. Alla maggior parte dei PoC viene assegnato un nome corrispondente alla tecnica.

Progetti

  • BlockingDLL : Questo toolset serve per testare il processo di blocco delle DLL. Vedi README.md.

  • CloneProcess : Questa directory è dedicata al forking e alla reflection dei processi. Vedi README.md.

  • CommandLineSpoofing : Questo PoC esegue lo spoofing della riga di comando. Questa tecnica potrebbe non funzionare su Windows 11.

  • DarkLoadLibrary : I PoC in questa directory servono per testare Dark Load Library, rilasciata da @_batsec_. Vedi README.md

  • GhostlyHollowing : Questo PoC esegue Ghostly Hollowing.

  • Misc : Questa directory contiene strumenti ausiliari per lo sviluppo dei PoC di questo repository.

  • PhantomDllHollower : Questo PoC esegue Phantom DLL Hollowing. Vedi README.md.

  • PPIDSpoofing : Questo PoC esegue PPID Spoofing.

  • ProcessDoppelgaenging : Questo PoC esegue Process Doppelgänging. A causa del miglioramento della protezione del kernel per Microsoft Defender, questa tecnica non funziona sui sistemi Windows recenti (dall'incirca 2021, forse). Quindi, se vuoi testare questa tecnica in un ambiente più nuovo, devi arrestare Microsoft/Windows Defender Antivirus Service. Vedi la issue del repository di hasherezade.

  • ProcessGhosting : Questo PoC esegue Process Ghosting. A causa della protezione del kernel, questa tecnica non funziona sui Windows più recenti a partire dalla 22H2.

  • ProcessHerpaderping : Questo PoC esegue Process Herpaderping. A causa del problema di blocco dei file, se scegli un file immagine fittizio più piccolo di quello che vuoi eseguire, la riduzione della dimensione del file fallirà e corromperà la firma del file per il processo herpaderping. Per sfruttare appieno questa tecnica, la dimensione del file immagine fittizio dovrebbe essere maggiore di quella del file che vuoi eseguire. A causa della protezione del kernel, questa tecnica non funziona sui Windows più recenti a partire dalla 22H2.

  • ProcessHollowing : Questo PoC esegue Process Hollowing. A differenza dell'originale, l'immagine PE viene analizzata in una nuova area di memoria invece di usare ZwUnmapViewOfSection / NtUnmapViewOfSection.

  • ProcMemScan : Questo è uno strumento diagnostico per investigare i processi remoti. Vedi README.md.

  • ProtectedProcess : Questo toolset serve per testare i Processi Protetti. Vedi README.md.

  • ReflectiveDLLInjection : Questo toolset serve per testare Reflective DLL Injection. Vedi README.md.

  • sRDI : Questa directory contiene lo strumento per sRDI (Shellcode Reflective DLL Injection). Vedi README.md.

  • TransactedHollowing : Questo PoC esegue Transacted Hollowing.

  • WmiSpawn : Questo PoC tenta di generare processi tramite WMI. I processi verranno generati come processi figli di WmiPrvSE.exe. Supporta l'esecuzione di processi su macchina locale e remota. L'uso è descritto in README.md.

  • NOTA : Attualmente il codice di ProcessHollowing non funziona con la build Debug. Per testarlo, usa la build Release. Vedi questa issue.

    Riferimenti

    Blocco DLL

    • Preventing 3rd Party DLLs from Injecting into your Malware

    • Staying Under the Radar - Part 1 - PPID Spoofing and Blocking DLLs

    • PPID Spoofing & BlockDLLs with NtCreateUserProcess

    Spoofing della riga di comando

    • Hide Artifacts: Process Argument Spoofing

    • The return of the spoof part 2: Command line spoofing

    Dark Load Library

    • GitHub - bats3c/DarkLoadLibrary

    • Bypassing Image Load Kernel Callbacks

    Phantom DLL Hollowing

    • Masking Malicious Memory Artifacts – Part I: Phantom DLL Hollowing

    • GitHub - forrest-orr/phantom-dll-hollower-poc

    PPID Spoofing

    • Access Token Manipulation: Parent PID Spoofing

    • Parent PID Spoofing (Mitre:T1134)

    • How to Detect Parent PID (PPID) Spoofing Attacks

    • Parent Process ID (PPID) Spoofing

    • The return of the spoof part 1: Parent process ID spoofing

    Process Doppelgänging

    • Lost in Transaction: Process Doppelgänging

    • Process Injection: Process Doppelgänging

    • Process Doppelgänging – a new way to impersonate a process

    Process Ghosting

    • What you need to know about Process Ghosting, a new executable image tampering attack

    • Process Ghosting Attack

    Process Herpaderping

    • GitHub - jxy-s/herpaderping

    • Process Herpaderping

    • Process Herpaderping (Mitre:T1055)

    Process Hollowing

    • Process Injection: Process Hollowing

    • Process Hollowing and Portable Executable Relocations

    Ghostly Hollowing e Transacted Hollowing

    • GitHub - hasherezade/transacted_hollowing

    Processo Protetto

    • Unknown Known DLLs

    • Unreal Mode : Breaking Protected Processes

    • The Evolution of Protected Processes – Part 1: Pass-the-Hash Mitigations in Windows 8.1

    • The Evolution of Protected Processes Part 2: Exploit/Jailbreak Mitigations, Unkillable Processes and Protected Services

    • Protected Processes Part 3 : Windows PKI Internals (Signing Levels, Scenarios, Root Keys, EKUs & Runtime Signers)

    • Windows Exploitation Tricks: Exploiting Arbitrary Object Directory Creation for Local Elevation of Privilege

    • Injecting Code into Windows Protected Processes using COM - Part 1

    • Injecting Code into Windows Protected Processes using COM - Part 2

    • Do You Really Know About LSA Protection (RunAsPPL)?

    • Bypassing LSA Protection in Userland

    • Debugging Protected Processes

    • The End of PPLdump

    • Protecting Windows protected processes

    • Relevance of Security Features Introduced in Modern Windows OS

    • Bypassing LSA Protection (aka Protected Process Light) without Mimikatz on Windows 10

    • Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpoint

    • Sandboxing Antimalware Products for Fun and Profit

    • GitHub - elastic/PPLGuard

    • GitHub - gabriellandau/PPLFault

    • PPLdump Is Dead. Long Live PPLdump (Video)

    • PPLdump Is Dead. Long Live PPLdump (Slide)

    Reflective DLL Injection

    • GitHub - stephenfewer/ReflectiveDLLInjection

    sRDI

    • sRDI – Shellcode Reflective DLL Injection

    • GitHub - monoxgas/sRDI

    • An Improved Reflective DLL Injection Technique

    Ringraziamenti

    Grazie per la vostra ricerca:

    • Tal Liberman (@tal_liberman)

    • Eugene Kogan (@EuKogan)

    • hasherezade (@hasherezade)

    • Gabriel Landau (@GabrielLandau)

    • Forrest Orr (@_forrestorr)

    • Stephen Fewer (@stephenfewer)

    • batsec (@_batsec_)

    • Nick Landers (@monoxgas)

    Scarica lo strumento