Snippet List

Technique Language Author OS Creation Date
Indirect Memory Writing Delphi DarkCoderSc 2 months, 2 weeks
Debug Registers, Hardware Breakpoints Python MatteoLodi 2 months, 3 weeks
Detecting Virtual Environment Artefacts C weirdraven 2 months, 3 weeks
Checking Pipe C HoIIovv 2 months, 3 weeks
Detecting Online Sandbox C# Futex 2 months, 3 weeks
WMI Event Subscriptions PowerShell 1d8 8 months, 1 week
Adding antivirus exception Python Malfav.Win32 9 months, 3 weeks
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 10 months, 2 weeks
Removing Commands from SELinux Audit Logs bash Unprotect 11 months
Deleting Troubleshoot Information and Core Dumps bash Unprotect 11 months
Manipulating Debug Logs bash Unprotect 11 months
XProtect Encryption Abuse Python 11 months
kernel flag inspection via sysctl Python fr0gger 11 months
Exfiltration via SMTP C# Tasdir 11 months
XBEL Recently Opened Files Check Python 1d8 11 months, 1 week
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 1 year
Default Windows Wallpaper Check Golang 1d8 1 year
Abusing the Return Pointer Assembly 0x_ror 1 year
Impossible Disassembly Rust Gelven 1 year
Detecting Virtual Environment Process C++ 0x_ror 1 year
Process Argument Spoofing Python Wietze 1 year
Process Argument Spoofing C Wietze 1 year
Event Triggered Execution: Linux Inotify Python 1d8 1 year
API Hammering C++ 0x_ror 1 year
Replication Through Removable Media Python 1d8 1 year, 1 month
QEMU CPU brand evasion C++ kernelwernel 1 year, 3 months
bochs CPU oversights evasion C++ kernelwernel 1 year, 3 months
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 1 year, 3 months
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 1 year, 3 months
AppInit DLL Injection C 1d8 1 year, 3 months

Filter