whereami
Environment extractor
A tool that extracts environment variables from a process without touching system DLLs using hand-crafted shellcode
Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.
160 stars
4 watching
28 forks
Language: C
last commit: over 2 years ago Related projects:
| Repository | Description | Stars |
|---|---|---|
| | A tool that enables remote process shellcode execution using the Early Bird injection technique | 267 |
| | An exploit tool that uses direct system calls to enumerate processes based on specific loaded modules or process handles | 266 |
| | Creates a tool to extract registry keys from Windows systems using a Beacon Object File | 188 |
| | A Cobalt Strike Beacon tool that spawns a sacrificial process to execute shellcode, using techniques like Arbitrary Code Guard and PPID spoofing to evade detection. | 440 |
| | A Cobalt Strike Beacon Object File (BOF) that uses custom syscaller code to make direct system calls to retrieve process information on the target system. | 95 |
| | An application designed to detect and extract hidden code from malicious Windows executables. | 270 |
| | An extension for Burp Suite to identify and extract interesting strings from web pages | 251 |
| | Tool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall | 276 |
| | A Beacon Object File Visual Studio template project for creating malicious code executables | 145 |
| | A framework for extracting information from unannotated text using large language models | 795 |
| | An extension for Burp Suite to extract parameters and endpoints from requests to create custom wordlists for testing | 140 |
| | This tool lists active Windows pipes and returns their owners and DACL permissions | 75 |
| | A tool to extract and format documentation from Ansible modules. | 16 |
| | Removes API hooks from a malicious process | 54 |
| | A Clojure library that captures and restores the local environment of a piece of code to simplify debugging | 578 |