ethicalhax (asaurusrex)

asaurusrex

Geek Repo

Github PK Tool:Github PK Tool

ethicalhax's repositories

Probatorum-EDR-Userland-Hook-Checker

Project to check which Nt/Zw functions your local EDR is hooking

Language:C++License:BSD-3-ClauseStargazers:179Issues:6Issues:0

DoppelGate

DoppelGate relies on reading ntdll on disk to grab syscall stubs, and patches these syscall stubs into desired functions to bypass Userland Hooking.

Language:C++License:NOASSERTIONStargazers:120Issues:4Issues:0

Forblaze

Forblaze - A Python Mac Steganography Payload Generator

Language:Objective-CLicense:BSD-3-ClauseStargazers:58Issues:3Issues:0

Rubicon

Caesar-Cipher based encryption

Language:C++License:NOASSERTIONStargazers:28Issues:4Issues:0

String_Spy

String Spy is a project aimed at improving MacOS/Linux defenses. It allows users to constantly monitor all running processes for user-defined strings, and if it detects a process with such a string it will log the PID, process path, and user running the process. It will also (optionally) kill the process.

Language:PythonLicense:BSD-3-ClauseStargazers:12Issues:1Issues:1

modified-tcc-clickjack

modified version of Ron Masas's TCC-Clickjack Swift project

Language:SwiftStargazers:7Issues:0Issues:0

Guard_Comms

C2 Guard Comms code base based on Guard Pages

Language:C++License:BSD-3-ClauseStargazers:5Issues:1Issues:0

Generate_DLLProxy_Header

Basic script to generate proxy DLL headers for side loading tests, will likely make prettier later

Language:PythonLicense:MITStargazers:2Issues:0Issues:0

ShellcodeFluctuation

An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents

Language:C++Stargazers:1Issues:0Issues:0

SleepyCrypt

A shellcode function to encrypt a running process image when sleeping.

Language:CLicense:GPL-3.0Stargazers:1Issues:0Issues:0

AceLdr

Cobalt Strike UDRL for memory scanner evasion.

Language:CLicense:MITStargazers:0Issues:0Issues:0

ANGRYORCHARD

A kernel exploit leveraging NtUserHardErrorControl to elevate a thread to KernelMode and achieve arbitrary kernel R/W & more.

Language:CStargazers:0Issues:0Issues:0
License:GPL-3.0Stargazers:0Issues:0Issues:0

FOLIAGE

Experiment on reproducing Obfuscate & Sleep

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

Stardust

A modern 64-bit position independent implant template

Stargazers:0Issues:0Issues:0

TCC-ClickJacking

A proof of concept for a clickjacking attack on macOS.

Stargazers:0Issues:0Issues:0

TitanLdr

Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH

Stargazers:0Issues:0Issues:0