gavinl1b0 (L1B0)

L1B0

Geek Repo

Company:School

Location:Beijing

Home Page:l1b0.github.io

Github PK Tool:Github PK Tool

gavinl1b0's starred repositories

BypassAntiVirus

远控免杀系列文章及配套工具,汇总测试了互联网上的几十种免杀工具、113种白名单免杀方式、8种代码编译免杀、若干免杀实战技术,并对免杀效果进行了一一测试,为远控的免杀和杀软对抗免杀提供参考。

BypassAV

This map lists the essential techniques to bypass anti-virus and EDR

SecurityInterviewGuide

网络信息安全从业者面试指南

SpoolFool

Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)

Language:C#License:MITStargazers:754Issues:16Issues:10

KillDefender

A small POC to make defender useless by removing its token privileges and lowering the token integrity

CVE-2021-1732-Exploit

CVE-2021-1732 Exploit

Language:C++Stargazers:412Issues:6Issues:0

-837-

哈尔滨工业大学考研 网络与空间安全 837 初试资料库

ProcessHider

Hide Process From Task Manager using Usermode API Hooking

getsymbol

Simple tool to download debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers compatible with Windows 8.1, 10 and 11

DefenderStop

Stop Defender Service using C# via Token Impersonation

awesome-malware-persistence

A curated list of awesome malware persistence tools and resources.

License:CC0-1.0Stargazers:162Issues:4Issues:0

Fuzzing

Fuzzing tutorial with easy-to-learn labs 🚀

Language:C++License:MITStargazers:154Issues:4Issues:0

KDStab

BOF combination of KillDefender and Backstab

Language:CLicense:MITStargazers:153Issues:5Issues:0

CVE-2020-1313

Proof of concept exploit of Windows Update Orchestrator Service Elevation of Privilege Vulnerability

bypass_vmp_vm_detect

bypass vmp virtual machine detect

avmext

Anti-Anti-VM solution via Windows Driver

Language:CLicense:MITStargazers:55Issues:8Issues:1
Language:PythonLicense:GPL-3.0Stargazers:47Issues:3Issues:0

IBM-RedCON-2020

IBM RedCON 2020 - Throwing an AquaWrench into the Kernel

hide-and-seek

PoC for hiding processes from Windows Task Manager by manipulating the graphic interface

Language:C++License:MITStargazers:40Issues:4Issues:1

anti-anti-vm-detection-dll

anti anti vm dll, used to hide VMWare characteristics as files, processes, services, registry values

Language:C++Stargazers:39Issues:3Issues:0

windows-kernel-file-protector

Protect a file from being deleted using windows kernel file system minifilter driver

Language:C++Stargazers:29Issues:0Issues:0

PowerBuilder-decompile

Python module that parse power builder file (PBD) and analyze code (Incomplete)

Language:PythonLicense:MITStargazers:14Issues:1Issues:3

CVE-2020-17136

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Language:C++Stargazers:6Issues:2Issues:0

FileHide

Hidding files from WinXP FileSystem

Language:C++License:MITStargazers:3Issues:0Issues:0

CVE-2020-1048

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'.

Language:CStargazers:2Issues:1Issues:0