Snippet List

Technique Language Author OS Creation Date
Indirect Memory Writing Delphi DarkCoderSc 1 month, 3 weeks
Debug Registers, Hardware Breakpoints Python MatteoLodi 2 months
Detecting Virtual Environment Artefacts C weirdraven 2 months
Checking Pipe C HoIIovv 2 months
Detecting Online Sandbox C# Futex 2 months
WMI Event Subscriptions PowerShell 1d8 7 months, 2 weeks
Adding antivirus exception Python Malfav.Win32 8 months, 4 weeks
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 9 months, 2 weeks
Removing Commands from SELinux Audit Logs bash Unprotect 10 months
Deleting Troubleshoot Information and Core Dumps bash Unprotect 10 months
Manipulating Debug Logs bash Unprotect 10 months
XProtect Encryption Abuse Python 10 months, 1 week
kernel flag inspection via sysctl Python fr0gger 10 months, 1 week
Exfiltration via SMTP C# Tasdir 10 months, 1 week
XBEL Recently Opened Files Check Python 1d8 10 months, 2 weeks
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 11 months, 2 weeks
Default Windows Wallpaper Check Golang 1d8 11 months, 2 weeks
Abusing the Return Pointer Assembly 0x_ror 11 months, 3 weeks
Impossible Disassembly Rust Gelven 11 months, 4 weeks
Detecting Virtual Environment Process C++ 0x_ror 1 year
Process Argument Spoofing Python Wietze 1 year
Process Argument Spoofing C Wietze 1 year
Event Triggered Execution: Linux Inotify Python 1d8 1 year
API Hammering C++ 0x_ror 1 year
Replication Through Removable Media Python 1d8 1 year, 1 month
QEMU CPU brand evasion C++ kernelwernel 1 year, 2 months
bochs CPU oversights evasion C++ kernelwernel 1 year, 2 months
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 year, 3 months
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 year, 3 months
AppInit DLL Injection C 1d8 1 year, 3 months

Filter