Elevator. UAC bypass by abusing RPC and debug objects.
631Shelter. ROP-based sleep obfuscation to evade memory scanners
388Unwinder. Call stack spoofing for Rust
383DInvoke_rs. Dynamically invoke arbitrary unmanaged code
366EPI. Threadless Process Injection through entry point hijacking
357MFTool. Direct access to NTFS volumes
296Split. Apply a divide and conquer approach to bypass EDRs
286Dumpy. Reuse open handles to dynamically dump LSASS.
247Fiber. Using fibers to run in-memory code.
246LOLBITS. ** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for EDR user-mode hooking evasion.
222ADPT. DLL proxying for lazy people
208Eclipse. Activation Context Hijack
181RustChain. Hide memory artifacts using ROP and hardware breakpoints.
150Bin-Finder. Detect EDR's exceptions by inspecting processes' loaded modules
133rust_tips_and_tricks. Rust For Windows Cheatsheet
122Puzzle. Set of PoC to abuse Windows minifilters functionality
94CustomEntryPoint. Select any exported function in a dll as the new dll's entry point.
83RustHollow. Inject a shellcode in a remote process using Process Hollowing.
54litcrypt.rs. A Rust compiler plugin to encrypt string literal at compile time.
22Scripts. Repository for dirty scripts and PoCs
20