Snippet List

Technique Language Author OS Creation Date
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 2 weeks, 6 days
Default Windows Wallpaper Check Golang 1d8 3 weeks, 2 days
Abusing the Return Pointer Assembly 0x_ror 4 weeks, 1 day
Impossible Disassembly Rust Gelven 1 month
Detecting Virtual Environment Process C++ 0x_ror 1 month, 1 week
Process Argument Spoofing Python Wietze 1 month, 1 week
Process Argument Spoofing C Wietze 1 month, 1 week
Event Triggered Execution: Linux Inotify Python 1d8 1 month, 1 week
API Hammering C++ 0x_ror 1 month, 1 week
Replication Through Removable Media Python 1d8 2 months, 1 week
QEMU CPU brand evasion C++ kernelwernel 3 months, 3 weeks
bochs CPU oversights evasion C++ kernelwernel 3 months, 3 weeks
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 4 months, 1 week
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 4 months, 1 week
AppInit DLL Injection C 1d8 4 months, 1 week
Hide Artifacts: Hidden Window C 1d8 4 months, 1 week
VboxEnumShares C++ HoIIovv 4 months, 1 week
Odd Thread Count C++ kernelwernel 4 months, 1 week
Hyper-V Signature C++ kernelwernel 4 months, 1 week
NtDelayExecution C d4rksystem 4 months, 1 week
APC injection FASM32 DarkCoderSc 7 months
Runtime Function Decryption Python irfan_eternal 9 months
Retrieve HDD Information C++ HoIIovv 9 months
BuildCommDCBAndTimeoutA C Huntress Research Team 9 months
Reflective DLL injection Delphi DarkCoderSc 1 year, 1 month
SMB / Named Pipes Delphi DarkCoderSc 1 year, 3 months
SMB / Named Pipes C# DarkCoderSc 1 year, 3 months
Right-to-Left Override (RLO) Extension Spoofing PowerShell DarkCoderSc 1 year, 4 months
Virtualization/Sandbox Evasion: Time Based Evasion Golang Edode 1 year, 5 months
DLL Unhooking C++ External 1 year, 5 months

Filter