Skip to content
View caueb's full-sized avatar

Block or report caueb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Pinned Loading

  1. ThreadlessStompingKann ThreadlessStompingKann Public

    Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.

    C 37 9

  2. Mockingjay Mockingjay Public

    Mockingjay process self injection POC

    C 13 5

  3. DInvoke-EarlyBird DInvoke-EarlyBird Public

    Early Bird process injection and PPID spoofing technique using DInvoke.

    C# 1

  4. mygistlist mygistlist Public

    1

  5. PayloadInResources PayloadInResources Public

    Simple AV bypass storing the shellcode in resources and XOR encrypting it.

    C++ 2

  6. PPIDSpoofing-BlockNonMSDlls PPIDSpoofing-BlockNonMSDlls Public

    Spawn a process spoofing the parent process and restrict non-Microsoft dlls to inject into the process.

    C 2