unknown

Kara-4search

Advanced
@Kara-4search

Security Researcher, SF-Express, Suanni, Redteam

NewNtdllBypassInlineHook_CSharp. Load a fresh new copy of ntdll.dll via file mapping to bypass API inline hook.

62

DInvoke_shellcodeload_CSharp. ShellCodeLoader via DInvoke

60

SysCall_ShellcodeLoad_Csharp. Load shellcode via syscall

55

HookDetection_CSharp. HookDetection

44

MappingInjection_CSharp. MappingInjection via csharp

39

PEB-PPIDspoofing_Csharp. Command line & PPID spoofing

31

EarlyBirdInjection_CSharp. Inject shellcode into process via "EarlyBird"

27

BypassETW_CSharp. Bypassing ETW with Csharp

26

Fiber_ShellcodeExecution. Using fibers to execute shellcode in a local process via csharp

26

WindowsEventLogsBypass_Csharp. Bypass windows eventlogs & Sysmon

18

ThreadHijacking_CSharp. Process inject technique "Thread hijacking" via csharp

16

HellgateLoader_CSharp. Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.

16

ProcessHollowing_CSharp. ProcessHollowing via csharp

13

APC_ShellcodeExecution_CSharp. Shellcode Load or execute via "APC technic"

13

BypassAMSI_CSharp. Bypass AMSI

12

Simple_ShellCodeLoader_CSharp. A Simple ShellcodeLoader

11

CreateThreadpoolWait_ShellcodeExecution_CSharp. Shellcode execution via CreateThreadpoolWait with Csharp

8

FullDLLUnhooking_CSharp. Unhook DLL via cleaning the DLL 's .text section

8

AddressOfEntryPoint_Hijack_CSharp. Shellcode injection or execution via AddressOfEntryPoint hijack.

8

JIT_DEMO_Csharp. A little JIT demo to help you understander how JIT works

6

AMSICheck_CSharp. A tool to detect the integrity of AmsiScanbuffer in memory ,and defend AMSI bypass

4

WinDefenderKiller. Windows Defender Killer | C++ Code Disabling Permanently Windows Defender using Registry Keys

3

Terminator. Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

3

PPLcontrol. Controlling Windows PP(L)s

3

ProjectPics. For temp pictures

3

KernelBypassSharp. C# Kernel Mode Driver to read and write memory in protected processes

3

defender-detectionhistory-parser. A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.

2

EDRs. C

2

test. test

1

DFSCoerce. Python

1

awesome-browser-exploit. awesome list of browser exploitation tutorials

1

ScareCrow. ScareCrow - Payload creation framework designed around EDR bypass.

1

discover. Custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit.

1

NET-Obfuscate. Obfuscate ECMA CIL (.NET IL) assemblies to evade Windows Defender AMSI

1

CVE-2021-40444_builders. This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit

1

LazySign. Create fake certs for binaries using windows binaries and the power of bat files

1

go-smash. Obfuscate go binaries. 混淆 go 二进制文件中的函数名

1
37
Apply