Snippet List

Technique Language Author OS Creation Date
Indirect Memory Writing Delphi DarkCoderSc 3 months, 2 weeks
Debug Registers, Hardware Breakpoints Python MatteoLodi 3 months, 4 weeks
Detecting Virtual Environment Artefacts C weirdraven 3 months, 4 weeks
Checking Pipe C HoIIovv 4 months
Detecting Online Sandbox C# Futex 4 months
WMI Event Subscriptions PowerShell 1d8 9 months, 2 weeks
Adding antivirus exception Python Malfav.Win32 10 months, 4 weeks
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 11 months, 2 weeks
Removing Commands from SELinux Audit Logs bash Unprotect 1 year
Deleting Troubleshoot Information and Core Dumps bash Unprotect 1 year
Manipulating Debug Logs bash Unprotect 1 year
XProtect Encryption Abuse Python 1 year
kernel flag inspection via sysctl Python fr0gger 1 year
Exfiltration via SMTP C# Tasdir 1 year
XBEL Recently Opened Files Check Python 1d8 1 year
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 1 year, 1 month
Default Windows Wallpaper Check Golang 1d8 1 year, 1 month
Abusing the Return Pointer Assembly 0x_ror 1 year, 1 month
Impossible Disassembly Rust Gelven 1 year, 1 month
Detecting Virtual Environment Process C++ 0x_ror 1 year, 2 months
Process Argument Spoofing Python Wietze 1 year, 2 months
Process Argument Spoofing C Wietze 1 year, 2 months
Event Triggered Execution: Linux Inotify Python 1d8 1 year, 2 months
API Hammering C++ 0x_ror 1 year, 2 months
Replication Through Removable Media Python 1d8 1 year, 3 months
QEMU CPU brand evasion C++ kernelwernel 1 year, 4 months
bochs CPU oversights evasion C++ kernelwernel 1 year, 4 months
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 year, 5 months
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 year, 5 months
AppInit DLL Injection C 1d8 1 year, 5 months

Filter