Snippet List

Technique Language Author Creation Date
QEMU CPU brand evasion C++ kernelwernel 1 month, 1 week
bochs CPU oversights evasion C++ kernelwernel 1 month, 2 weeks
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 month, 3 weeks
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 month, 3 weeks
AppInit DLL Injection C 1d8 1 month, 3 weeks
Hide Artifacts: Hidden Window C 1d8 1 month, 3 weeks
VboxEnumShares C++ HoIIovv 1 month, 3 weeks
Odd Thread Count C++ kernelwernel 1 month, 3 weeks
Hyper-V Signature C++ kernelwernel 1 month, 3 weeks
NtDelayExecution C d4rksystem 1 month, 3 weeks
APC injection FASM32 DarkCoderSc 4 months, 3 weeks
Runtime Function Decryption Python irfan_eternal 6 months, 3 weeks
Retrieve HDD Information C++ HoIIovv 6 months, 3 weeks
BuildCommDCBAndTimeoutA C Huntress Research Team 6 months, 3 weeks
Reflective DLL injection Delphi DarkCoderSc 10 months, 3 weeks
SMB / Named Pipes Delphi DarkCoderSc 1 year, 1 month
SMB / Named Pipes C# DarkCoderSc 1 year, 1 month
Right-to-Left Override (RLO) Extension Spoofing PowerShell DarkCoderSc 1 year, 2 months
Virtualization/Sandbox Evasion: Time Based Evasion Golang Edode 1 year, 2 months
DLL Unhooking C++ External 1 year, 3 months
Shikata Ga Nai (SGN) bash Dreamkinn 1 year, 3 months
Process Reimaging C++ 一半人生 1 year, 3 months
Process Ghosting C++ 一半人生 1 year, 3 months
C2 via FTP(S) Delphi DarkCoderSc 1 year, 4 months
C2 via FTP(S) C# DarkCoderSc 1 year, 4 months
Checking Specific Folder Name C++ 一半人生 1 year, 4 months
VMCPUID C++ 一半人生 1 year, 4 months
Evasion using direct Syscalls C++ ghost_pepper108 1 year, 4 months
GetForegroundWindow Golang Edode 1 year, 5 months
Connected Printer Golang Edode 1 year, 5 months

Filter