TamperingSyscalls. C++
509BootExecuteEDR. C
419misc. miscellaneous scripts and programs
287hwbp4mw. C++
273WTSRM. WTSRM
215byor. Go
166WTSRM2. C++
164PMD. C++
159FileRenameJunctionsEDRDisable. C++
159VehApiResolve. C++
118talks.
73BloatedHammer. API Hammering with C++20
53RansomFS. C++
31DriverJack. Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
4Zeus. NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. This repository is for study purposes only, do not message me about your lame hacking attempts.
2shellcode-template. A cmkr based win32 shellcode template for a unified build platform and more production friendly structure/testing.
1detection-rules. Python
1