Snippet List

Technique Language Author OS Creation Date
Indirect Memory Writing Delphi DarkCoderSc 1 week, 1 day
Debug Registers, Hardware Breakpoints Python MatteoLodi 2 weeks, 4 days
Detecting Virtual Environment Artefacts C weirdraven 2 weeks, 4 days
Checking Pipe C HoIIovv 2 weeks, 4 days
Detecting Online Sandbox C# Futex 2 weeks, 4 days
WMI Event Subscriptions PowerShell 1d8 6 months
Adding antivirus exception Python Malfav.Win32 7 months, 2 weeks
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 8 months, 1 week
Removing Commands from SELinux Audit Logs bash Unprotect 8 months, 3 weeks
Deleting Troubleshoot Information and Core Dumps bash Unprotect 8 months, 3 weeks
Manipulating Debug Logs bash Unprotect 8 months, 3 weeks
XProtect Encryption Abuse Python 8 months, 3 weeks
kernel flag inspection via sysctl Python fr0gger 8 months, 3 weeks
Exfiltration via SMTP C# Tasdir 8 months, 4 weeks
XBEL Recently Opened Files Check Python 1d8 9 months
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 10 months
Default Windows Wallpaper Check Golang 1d8 10 months
Abusing the Return Pointer Assembly 0x_ror 10 months, 1 week
Impossible Disassembly Rust Gelven 10 months, 2 weeks
Detecting Virtual Environment Process C++ 0x_ror 10 months, 2 weeks
Process Argument Spoofing Python Wietze 10 months, 2 weeks
Process Argument Spoofing C Wietze 10 months, 2 weeks
Event Triggered Execution: Linux Inotify Python 1d8 10 months, 2 weeks
API Hammering C++ 0x_ror 10 months, 2 weeks
Replication Through Removable Media Python 1d8 11 months, 2 weeks
QEMU CPU brand evasion C++ kernelwernel 1 year, 1 month
bochs CPU oversights evasion C++ kernelwernel 1 year, 1 month
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 year, 1 month
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 year, 1 month
AppInit DLL Injection C 1d8 1 year, 1 month

Filter