Self_Deletion_BOF

Process killer

BOF implementation of a research concept allowing for controlled deletion of processes

BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs

GitHub

171 stars
2 watching
23 forks
Language: C
last commit: almost 5 years ago

Related projects:

RepositoryDescriptionStars
espressocake/ppldump_bofA tool for dumping the memory contents of a protected process on Windows136
espressocake/process_protection_level_bofA tool that helps operators determine the protection level of a process before attempting to access its memory51
espressocake/defender_exclusions-bofTools to determine Windows Defender exclusions241
espressocake/dll-hijack-search-order-bofA tool to enumerate the search order of DLL resolution and potentially gain information about a file's mutability.141
espressocake/firewall_walker_bofAn exploit technique allowing interaction with Windows software firewall via COM interfaces.100
espressocake/toggle_token_privileges_bofA tool to add or remove specific privilege rights from the token of the current process52
espressocake/needle_sift_bofA tool for searching for specific strings within files using a needle-sift algorithm30
seventeenman/selfdel-bofDeletes files regardless of handle occupation to bypass system restrictions40
espressocake/dll_imports_bofAn enumeration tool to inspect PE files and extract information about loaded DLLs and their imported functions83
klezvirus/sharpselfdeleteImplementation of a Windows exploitation technique using P/Invoke to delete processes from memory147
like0x/adddefenderexclusions-bofA tool to add exclusions to a security system's defender to prevent false positives or unwanted alerts32
lloydlabs/delete-self-pocA tool to delete locked or running files from disk by manipulating the current process's handle and file disposition505
outflanknl/findobjects-bofAn exploit tool that uses direct system calls to enumerate processes based on specific loaded modules or process handles266
octoberfest7/killdefender_bofA tool that allows an attacker to elevate privileges and gain control over the Windows Defender service62
heppu/gkillAn interactive process killer tool for Linux and macOS that allows users to filter and kill processes using keyboard navigation.316