Lloyd Davies (LloydLabs)

LloydLabs

Geek Repo

Company:@CrowdStrike

Location:London

Home Page:https://blog.syscall.party

Twitter:@LloydLabs

Github PK Tool:Github PK Tool

Lloyd Davies's repositories

delete-self-poc

A way to delete a locked file, or current running executable, on disk.

Language:CLicense:MITStargazers:477Issues:17Issues:3

wsb-detect

wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")

Language:CLicense:MITStargazers:345Issues:14Issues:0

Windows-API-Hashing

This is a simple example and explanation of obfuscating API resolution via hashing

ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection.

Language:CLicense:MITStargazers:221Issues:3Issues:2

shellcode-plain-sight

Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak

Language:CLicense:MITStargazers:162Issues:6Issues:0

elf-strings

elf-strings will programmatically read an ELF binary's string sections within a given binary. This is meant to be much like the strings UNIX utility, however is purpose built for ELF binaries.

Language:GoStargazers:138Issues:6Issues:0

dearg-thread-ipc-stealth

A novel technique to communicate between threads using the standard ETHREAD structure

Language:CStargazers:102Issues:8Issues:0

librini

Rini is a tiny, non-libc dependant, .ini file parser programmed from scratch in C99.

Language:CLicense:MITStargazers:28Issues:5Issues:2

go-malwarebazaar

MalwareBazaar public API bindings for Go

Language:GoStargazers:7Issues:3Issues:0

sgrm-research

Repository to compliment my blog post on System Guard Runtime Monitor

Language:LuaStargazers:4Issues:2Issues:0

pafish-macos

A macOS pafish-like port to detect analysis/virtual environments

pefile

pefile is a Python module to read and work with PE (Portable Executable) files

Language:PythonLicense:MITStargazers:1Issues:1Issues:0

yara

The pattern matching swiss knife

Language:CLicense:BSD-3-ClauseStargazers:1Issues:0Issues:0