HOLLOW

Shellcode injector

A tool that enables remote process shellcode execution using the Early Bird injection technique

EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and execute shellcode

GitHub

267 stars
10 watching
57 forks
Language: C
last commit: over 3 years ago

Related projects:

RepositoryDescriptionStars
boku7/spawnA Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection.440
tomcarver16/bof-dll-injectA tool for injecting malware into processes by mapping it to memory without registering it with the kernel.147
boku7/injectamsibypassA tool that bypasses AMSI in a remote process with code injection.377
iilegacyyii/threadlessinject-bofA tool that enables process injection without thread creation by hooking an export function from a remote process.369
boku7/whereamiA tool that extracts environment variables from a process without touching system DLLs using hand-crafted shellcode160
hasherezade/transacted_hollowingAn implementation of a memory-based PE injection technique for executing payloads in a target process521
boku7/injectetwbypassTool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall276
boku7/halosgate-psA Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system.95
plackyhacker/shellcode-injection-techniquesA collection of C# techniques for injecting malicious shellcode into processes450
droberson/papa-shangoAn assembler-based tool to inject shellcode into running processes on Linux using ptrace(), allowing for controlled modification of process behavior.5
apokryptein/secinjectA tool for injecting malicious code into processes using native APIs and memory section mapping.88
outflanknl/findobjects-bofAn exploit tool that uses direct system calls to enumerate processes based on specific loaded modules or process handles266
chvancooten/nimplantA lightweight implant tool allowing users to create and execute custom in-memory operations on Windows810
bronzeticket/clipboardwindow-injectA tool that injects malicious code into the clipboard window of a remote process to execute custom shellcode65
dtmsecurity/bof_helperCreates C programs with custom API calls using Microsoft's documentation endpoint and grep results from mingw header files222