Lloyd Davies (LloydLabs)

LloydLabs

Geek Repo

Company:CrowdStrike

Location:London

Home Page:https://blog.syscall.party

Twitter:@LloydLabs

Github PK Tool:Github PK Tool

Lloyd Davies's repositories

delete-self-poc

A way to delete a locked file, or current running executable, on disk.

Language:CLicense:MITStargazers:482Issues:18Issues:3

wsb-detect

wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")

Language:CLicense:MITStargazers:349Issues:14Issues:1

ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection.

Language:CLicense:MITStargazers:228Issues:4Issues:2

Windows-API-Hashing

This is a simple example and explanation of obfuscating API resolution via hashing

shellcode-plain-sight

Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak

Language:CLicense:MITStargazers:165Issues:6Issues:0

elf-strings

elf-strings will programmatically read an ELF binary's string sections within a given binary. This is meant to be much like the strings UNIX utility, however is purpose built for ELF binaries.

Language:GoStargazers:139Issues:6Issues:0

dearg-thread-ipc-stealth

A novel technique to communicate between threads using the standard ETHREAD structure

Language:CStargazers:106Issues:8Issues:0

librini

Rini is a tiny, non-libc dependant, .ini file parser programmed from scratch in C99.

Language:CLicense:MITStargazers:29Issues:5Issues:2

go-malwarebazaar

MalwareBazaar public API bindings for Go

Language:GoStargazers:8Issues:3Issues:0

sgrm-research

Repository to compliment my blog post on System Guard Runtime Monitor

Language:LuaStargazers:5Issues:2Issues:0

pafish-macos

A macOS pafish-like port to detect analysis/virtual environments

pefile

pefile is a Python module to read and work with PE (Portable Executable) files

Language:PythonLicense:MITStargazers:1Issues:1Issues:0

yara

The pattern matching swiss knife

Language:CLicense:BSD-3-ClauseStargazers:1Issues:1Issues:0