ThreadStackSpoofer

Evasion technique

An advanced in-memory evasion technique to hide injected shellcode's memory allocation from scanners and analysts.

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

GitHub

1k stars
28 watching
177 forks
Language: C++
last commit: over 4 years ago

Related projects:

RepositoryDescriptionStars
mgeeky/shellcodefluctuationAn advanced in-memory evasion technique for hiding malicious code from scanners by fluctuating shellcode's memory protection and encrypting its contents.957
mgeeky/redwardenA tool to evade detection by security systems and incident responders by manipulating HTTP requests933
arvanaghi/checkpleaseA collection of sandbox evasion modules written in various programming languages.904
kyleavery/aceldrA Cobalt Strike memory scanner evasion technique using code obfuscation and encryption to evade detection.887
zha0gongz1/desertfoxA Go-based tool for loading and executing malicious shellcode while evading anti-virus detection125
apehex/web3-evasion-techniquesA comprehensive repository detailing web3 evasion techniques and their application in malware detection.4
joshfaust/alarisA low-level shellcode loader that defeats modern EDR systems by utilizing various evasion techniques and encryption.891
epi052/rustdsplitRe-implements a method to bypass signature-based AV detection by splitting a file into two halves and modifying one byte in each half to evade detection.35
0xsp-srd/mortarA toolset designed to evade detection by security products and execute malware safely1,421
rkervella/carbonmonoxideA toolkit for evading endpoint detection and response (EDR) by combining techniques to spoof system properties and inject malicious code.24
wkl-sec/malleable-cs-profilesA collection of tools to generate and modify shellcode profiles to evade detection in Cobalt Strike384
hangingsword/houqingA tool for generating and uploading malicious executable files to evade antivirus detection206
aetsu/offensivepipelineA tool for modifying and building C# tools to evade detection in Red Team exercises791
mgeeky/stracciatellaA tool to bypass security features in PowerShell and create an unmanaged environment for executing malicious code509
b4rtik/hiddenpowershelldllA PowerShell evasion tool that uses a DLL to bypass security measures and execute a hidden stager93