Ricardo Ruiz 's repositories

wifi-pentesting-guide

WiFi Penetration Testing Guide

NativeDump

Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)

WhoamiAlternatives

Different methods to get current username without using whoami

Language:C#Stargazers:172Issues:2Issues:0

covert-tube

Youtube as covert-channel - Control systems remotely and execute commands by uploading videos to Youtube

Language:PythonStargazers:105Issues:4Issues:0

SharpCovertTube

Youtube as C2 - Control Windows systems uploading videos to Youtube

instagram-user-id

Get the user ID of any user in instagram

spotify-playlist-downloader

Downloading Spotify Playlists

p-invoke.net

P/Invoke definitions from the now offline pinvoke.net - Website: https://www.p-invoke.net/

OSED-prep

Exploits written while preparing for the OSED exam

Language:PythonStargazers:17Issues:1Issues:0

SharpObfuscate

Obfuscate payloads using IPv4, IPv6, MAC or UUID strings

Language:C#Stargazers:11Issues:1Issues:0

SharpNado

Repository to gather all .NET malware related code snippets or programs I will develop

Stargazers:8Issues:0Issues:0

jeringuilla

Process injection framework in C#. It uses dynamic function loading using delegates and AES-encryption for strings and payloads

Language:C#Stargazers:7Issues:1Issues:0

MinidumpParser

C# program to parse Microsoft Minidump files and their streams

Language:C#Stargazers:7Issues:2Issues:0

SharpNtdllOverwrite

Overwrite ntdll.dll's ".text" section to bypass API hooking. Getting the clean dll from disk, Knowndlls folder, a debugged process or a URL

Language:C#Stargazers:6Issues:1Issues:0

GetProcAddress

GetProcAddress implementation in C# walking the PEB using only ReadProcessMemory

Language:C#Stargazers:5Issues:1Issues:0

SharpProcessDump

Dump memory regions of a process using NtQueryVirtualMemory and NtReadVirtualMemory

Language:C#Stargazers:5Issues:0Issues:0

SharpSelfDelete

PoC to self-delete a binary in C#

Language:C#Stargazers:5Issues:0Issues:0

GetModuleHandle

GetModuleHandle implementation in C# using only NtQueryInformationProcess by walking the PEB

Language:C#Stargazers:4Issues:1Issues:0

StealthyEnv

Stealthier alternative to whoami.exe in C#, it gets environment variables from PEB (PRTL_USER_PROCESS_PARAMETERS)

Language:C#Stargazers:4Issues:1Issues:0

botnet-ssh-control

Botnet Command and Control (C&C) controlled via SSH. Based in Paramiko library

Language:PythonStargazers:3Issues:1Issues:0

dns-exfiltration

Notes and custom scripts for DNS exfiltration

Language:PythonStargazers:2Issues:1Issues:0

lsass-dumper-csharp

Custom lsass.exe dump using C#: XOR-encoding, Dynamic function resolution, using NTAPIs...

Language:C#Stargazers:2Issues:1Issues:0

rop-emporium-exploits

Rop Emporium - Exploits and brief Walkthroughs

Language:PythonStargazers:2Issues:1Issues:0

GetModuleHandleRemote

GetModuleHandle implementation in C# for remote processes using only NTAPIs

Language:C#Stargazers:1Issues:0Issues:0

go-GetProcessByName

Get process handle(s) from process name using NtGetNextProcess and GetProcessImageFileName

Language:GoStargazers:1Issues:0Issues:0

niidoru

Framework for Process Injection in Windows using Go

Language:GoStargazers:1Issues:0Issues:0
Language:SCSSStargazers:1Issues:1Issues:0

pyNtdllOverwrite

Overwrite ntdll.dll's ".text" section to bypass API hooking. Getting the clean dll from disk, Knowndlls folder or a debugged process

Language:PythonStargazers:0Issues:0Issues:0

ricardojoserf

Github profile readme

Stargazers:0Issues:1Issues:0
Language:PythonStargazers:0Issues:2Issues:0