XaFF (XaFF-XaFF)

XaFF-XaFF

Geek Repo

Company:TalosSec

Location:Poland

Home Page:xaff.dev

Twitter:@0xXaFF

Github PK Tool:Github PK Tool

XaFF's repositories

Cronos-Rootkit

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Language:C++License:MITStargazers:797Issues:24Issues:13

Black-Angel-Rootkit

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

Language:C++License:GPL-3.0Stargazers:569Issues:9Issues:4

CaveCarver

CaveCarver - PE backdooring tool which utilizes and automates code cave technique

Language:C++License:MITStargazers:184Issues:7Issues:3

Kernel-Process-Hollowing

Windows x64 kernel mode rootkit process hollowing POC.

Language:C++License:MITStargazers:176Issues:4Issues:0

Shellcodev

Shellcodev is a tool designed to help and automate the process of shellcode creation.

Language:C++License:MITStargazers:98Issues:5Issues:0

ZwProcessHollowing

ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption

Language:C++Stargazers:75Issues:3Issues:0

2Simple-Dll-Injector

C# DLL Injector written as simple as possible

Heap-Injection

Example of C# heap injector for x64 and x86 shellcodes

MBR-Overwrite-with-custom-message

Overwrite MBR and add own custom message

Watykanczyk

Remake znanego wirusa Watykańczyka w C#

Language:C#Stargazers:15Issues:1Issues:0

2Simple-Keylogger

Simple keylogger written in C# which is ready for modifications.

Language:C#Stargazers:12Issues:3Issues:0

AMSI-Bypass

Rasta's mouse AMSI patch but with function that makes it undetectable.

Language:C#Stargazers:12Issues:2Issues:0

WinREPL

WinREPL is a "read-eval-print loop" shell on Windows that is useful for testing/learning x86 and x64 assembly.

Language:C++License:ZlibStargazers:11Issues:2Issues:0

Assembler-MessageBox

An Assembly x86 code that shows Windows MessageBox kept as simple as possible.

Language:AssemblyLicense:MITStargazers:10Issues:1Issues:0

Discord-Webhook-Cannon

Discord Webhook Cannon is a C# multithreaded, open-source Discord Webhook flooder. It can be used to flood webhooks which are used in malware.

Language:C#License:GPL-3.0Stargazers:8Issues:1Issues:0

Win_Rootkit

A kernel-mode rootkit with remote control

Language:C++Stargazers:3Issues:0Issues:0
Language:HTMLStargazers:1Issues:1Issues:0

WinXRunPE

💉 Two C# RunPE's capable of x86 and x64 injections 💉

Language:C#License:MITStargazers:1Issues:1Issues:0
Language:HTMLStargazers:0Issues:1Issues:0
Stargazers:0Issues:1Issues:0