XaFF
XaFF
Cronos-Rootkit
Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
Shellcodev
Shellcodev is a tool designed to help and automate the process of shellcode creation.
ZwProcessHollowing
ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption
Heap-Injection
Example of C# heap injector for x64 and x86 shellcodes
Black-Angel-Rootkit
Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.
CaveCarver
CaveCarver - PE backdooring tool which utilizes and automates code cave technique
Kernel-Process-Hollowing
Windows x64 kernel mode rootkit process hollowing POC.