Marcos Oviedo's repositories

nanodump

Dump LSASS like you mean it

Language:CLicense:Apache-2.0Stargazers:3Issues:1Issues:0

kdmapper

KDMapper is a simple tool that exploits iqvw64e.sys Intel driver to manually map non-signed drivers in memory

Language:C++License:MITStargazers:2Issues:1Issues:0

RefleXXion

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first collects the syscall numbers of the NtOpenFile, NtCreateSection, NtOpenSection and NtMapViewOfSection found in the LdrpThunkSignature array.

Language:C++Stargazers:2Issues:1Issues:0
Language:CLicense:Apache-2.0Stargazers:1Issues:1Issues:0

MalMemDetect

Detect strange memory regions and DLLs

Language:C++License:GPL-3.0Stargazers:1Issues:1Issues:0

SinMapper

usermode driver mapper that forcefully loads any signed kernel driver (legit cert) with a big enough section (example: .data, .rdata) to map your driver over. the main focus of this project is to prevent modern anti-cheats (BattlEye, EAC) from finding your driver and having the power to hook anything due to being inside of legit memory (signed legit driver).

Language:C++Stargazers:1Issues:1Issues:0

TokenStomp

C# implementation of the token privilege removal flaw discovered by @GabrielLandau/Elastic

Language:C#Stargazers:1Issues:1Issues:0

BackupOperatorToDA

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

Language:C++Stargazers:0Issues:1Issues:0

CandyPotato

Pure C++, weaponized, fully automated implementation of RottenPotatoNG

Language:C++License:GPL-3.0Stargazers:0Issues:1Issues:0

capa-rules

Standard collection of rules for capa: the tool for enumerating the capabilities of programs

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0
Language:C++Stargazers:0Issues:1Issues:0

FindETWProviderImage

Quickly search for references to a GUID in DLLs, EXEs, and drivers

Language:C#License:BSD-3-ClauseStargazers:0Issues:0Issues:0

Hunt-Sleeping-Beacons

Aims to identify sleeping beacons

Language:CStargazers:0Issues:1Issues:0

LiquidSnake

LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript

Language:C#Stargazers:0Issues:1Issues:0

MalSeclogon

A little tool to play with the Seclogon service

Language:CLicense:GPL-3.0Stargazers:0Issues:1Issues:0

PDBRipper

PDBRipper is a utility for extract an information from PDB-files.

Language:C++License:MITStargazers:0Issues:1Issues:0

PR0CESS

some gadgets about windows process and ready to use :)

Language:CLicense:Apache-2.0Stargazers:0Issues:1Issues:0

Privexec

Run the program with the specified permission level (C++17 required)

Language:C++License:MITStargazers:0Issues:1Issues:0

process-governor

This application allows you to put various limits on a Windows process.

License:MITStargazers:0Issues:0Issues:0

RestrictedAdmin

Remotely enables Restricted Admin Mode

Language:C#License:BSD-3-ClauseStargazers:0Issues:1Issues:0

shakeitoff

Windows LPE 0-day

Language:C++License:BSD-3-ClauseStargazers:0Issues:1Issues:0

small

C++ small containers

Language:C++License:MITStargazers:0Issues:1Issues:0

unDefender

Killing your preferred antimalware by abusing native symbolic links and NT paths.

Language:C++Stargazers:0Issues:1Issues:0

unicorn_pe

Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.

Language:CLicense:MITStargazers:0Issues:1Issues:0

windows-hardening-scripts

Windows 10/11 hardening scripts

Language:BatchfileLicense:GPL-3.0Stargazers:0Issues:1Issues:0

winrmdll

C++ WinRM API via Reflective DLL

License:MITStargazers:0Issues:0Issues:0

WinSys

C++ library for low-level Windows development

Language:CStargazers:0Issues:1Issues:0

WPBT-Builder

The simple UEFI application to create a Windows Platform Binary Table (WPBT) from the UEFI shell.

Language:CLicense:MITStargazers:0Issues:1Issues:0

xntsv

XNTSV program for detailed viewing of system structures for Windows.

Language:QMakeLicense:MITStargazers:0Issues:1Issues:0

zerosharp

Demo of the potential of C# for systems programming with the .NET native ahead-of-time compilation technology.

Language:C#Stargazers:0Issues:1Issues:0