6 results found Sort:
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
Created
2024-02-22
31 commits to main branch, last one about a month ago
Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!
Created
2024-06-24
53 commits to main branch, last one about a month ago
Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
Created
2024-12-01
20 commits to main branch, last one about a month ago
Inline syscalls made for MSVC supporting x64 and WOW64
Created
2023-04-03
13 commits to master branch, last one about a year ago
A Dropper POC with a focus on aiding in EDR evasion, NTDLL Unhooking followed by loading ntdll in-memory, which is present as shellcode (using pe2shc by @hasherezade). Payload encryption via SystemFuc...
Created
2023-01-30
20 commits to main branch, last one about a year ago
Bypass the Event Trace Windows(ETW) and unhook ntdll.
Created
2023-09-25
6 commits to main branch, last one about a year ago