Snippet List

Technique Language Author OS Creation Date
WMI Event Subscriptions PowerShell 1d8 4 months, 2 weeks
Adding antivirus exception Python Malfav.Win32 5 months, 4 weeks
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 6 months, 2 weeks
Removing Commands from SELinux Audit Logs bash Unprotect 7 months
Deleting Troubleshoot Information and Core Dumps bash Unprotect 7 months
Manipulating Debug Logs bash Unprotect 7 months
XProtect Encryption Abuse Python 7 months, 1 week
kernel flag inspection via sysctl Python fr0gger 7 months, 1 week
Exfiltration via SMTP C# Tasdir 7 months, 1 week
XBEL Recently Opened Files Check Python 1d8 7 months, 1 week
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 8 months, 1 week
Default Windows Wallpaper Check Golang 1d8 8 months, 2 weeks
Abusing the Return Pointer Assembly 0x_ror 8 months, 3 weeks
Impossible Disassembly Rust Gelven 8 months, 4 weeks
Detecting Virtual Environment Process C++ 0x_ror 8 months, 4 weeks
Process Argument Spoofing Python Wietze 9 months
Process Argument Spoofing C Wietze 9 months
Event Triggered Execution: Linux Inotify Python 1d8 9 months
API Hammering C++ 0x_ror 9 months
Replication Through Removable Media Python 1d8 10 months
QEMU CPU brand evasion C++ kernelwernel 11 months, 2 weeks
bochs CPU oversights evasion C++ kernelwernel 11 months, 2 weeks
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 year
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 year
AppInit DLL Injection C 1d8 1 year
Hide Artifacts: Hidden Window C 1d8 1 year
VboxEnumShares C++ HoIIovv 1 year
Odd Thread Count C++ kernelwernel 1 year
Hyper-V Signature C++ kernelwernel 1 year
NtDelayExecution C d4rksystem 1 year

Filter