Snippet List

Technique Language Author OS Creation Date
System Binary Proxy Execution: Rundll32 Delphi DarkCoderSc 6 days, 6 hours
Removing Commands from SELinux Audit Logs bash Unprotect 2 weeks, 6 days
Deleting Troubleshoot Information and Core Dumps bash Unprotect 2 weeks, 6 days
Manipulating Debug Logs bash Unprotect 2 weeks, 6 days
XProtect Encryption Abuse Python 3 weeks, 4 days
kernel flag inspection via sysctl Python fr0gger 3 weeks, 4 days
Exfiltration via SMTP C# Tasdir 3 weeks, 6 days
XBEL Recently Opened Files Check Python 1d8 4 weeks, 2 days
Virtualization/Sandbox Evasion: User Activity Based Checks Python 1d8 1 month, 4 weeks
Default Windows Wallpaper Check Golang 1d8 2 months
Abusing the Return Pointer Assembly 0x_ror 2 months, 1 week
Impossible Disassembly Rust Gelven 2 months, 2 weeks
Detecting Virtual Environment Process C++ 0x_ror 2 months, 2 weeks
Process Argument Spoofing Python Wietze 2 months, 2 weeks
Process Argument Spoofing C Wietze 2 months, 2 weeks
Event Triggered Execution: Linux Inotify Python 1d8 2 months, 2 weeks
API Hammering C++ 0x_ror 2 months, 2 weeks
Replication Through Removable Media Python 1d8 3 months, 2 weeks
QEMU CPU brand evasion C++ kernelwernel 5 months
bochs CPU oversights evasion C++ kernelwernel 5 months
Impair Defenses: Disable Windows Event Logging PowerShell 0x0d4y 5 months, 2 weeks
Impair Defenses: Disable Windows Event Logging bash 0x0d4y 5 months, 2 weeks
AppInit DLL Injection C 1d8 5 months, 2 weeks
Hide Artifacts: Hidden Window C 1d8 5 months, 2 weeks
VboxEnumShares C++ HoIIovv 5 months, 2 weeks
Odd Thread Count C++ kernelwernel 5 months, 2 weeks
Hyper-V Signature C++ kernelwernel 5 months, 2 weeks
NtDelayExecution C d4rksystem 5 months, 2 weeks
APC injection FASM32 DarkCoderSc 8 months, 2 weeks
Runtime Function Decryption Python irfan_eternal 10 months, 2 weeks

Filter