-
DC949
- Baltimore, MD
Stars
My implementation of enSilo's Process Doppelganging (PE injection technique)
A set of fully-undetectable process injection techniques abusing Windows Thread Pools
An implementation of pointer encryption to prevent easy-access of reading and writing to pointers in memory.
Minimal PoC developed as discuss in https://captmeelo.com/redteam/maldev/2022/05/10/ntcreateuserprocess.html
rasta-mouse / ThreatCheck
Forked from matterpreter/DefenderCheckIdentifies the bytes that Microsoft Defender / AMSI Consumer flags on.
Assets for the "Tickling VMProtect with LLVM" blog post.
Framework for lifting x86, amd64, aarch64, sparc32, and sparc64 program binaries to LLVM bitcode
This map lists the essential techniques to bypass anti-virus and EDR
Parse and extract data from Microsoft LZX compressed .cab files for Java 6+
A C library for reading, creating, and modifying zip archives.
A C++ static library offering a clean and simple interface to the 7-zip shared libraries.
A C++ library and tools for demangling mangled C++ names.
Commandline toolkit to handle Windows icon files(*.ICO)
Hypervisor based anti anti debug plugin for x64dbg
Allows you to find the use of ScyllaHide, if your program will debug and restore hooking functions bytes.
Bitmap arrays for rendering CP437 glyphs using IBM PC OEM fonts
Mikmod Sound System (mirror of git repo at https://sf.net/projects/mikmod/)