Snippet List

Technique Language Author Creation Date
Indicator Removal: Timestomp C# DarkCoderSc 1 year, 11 months
Hijack Execution Flow: DLL Search Order Hijacking C++ Sh0ckFR 1 year, 11 months
DLL Proxying C++ Sh0ckFR 1 year, 11 months
DLL Proxying Python Sh0ckFR 1 year, 11 months
Change Module Base Address at Runtime C++ Alex Schwarz 2 years
Change Module Name at Runtime C++ Alex Schwarz 2 years
FLIRT Signatures Evasion Assembly Lexsek 2 years
Windows Event Log Evasion via Native APIs C++ External 2 years
Process Hollowing, RunPE Delphi DarkCoderSc 2 years
RDTSC C++ External 2 years, 1 month
NtQueryObject C++ External 2 years, 1 month
CsrGetProcessID C++ External 2 years, 1 month
CloseHandle, NtClose C++ External 2 years, 1 month
Heap Flag C++ External 2 years, 1 month
GetTickCount C++ External 2 years, 1 month
GetLocalTime, GetSystemTime, timeGetTime, NtQueryPerformanceCounter C++ External 2 years, 1 month
Performing Code Checksum C++ External 2 years, 1 month
Unhandled Exception Filter C++ External 2 years, 1 month
Trap Flag C++ External 2 years, 1 month
INT 0x2D C++ External 2 years, 1 month
Trap Flag Assembly External 2 years, 1 month
ICE 0xF1 Assembly External 2 years, 1 month
INT 0x2D Assembly External 2 years, 1 month
INT3 Instruction Scanning Assembly External 2 years, 1 month
INT3 Instruction Scanning C++ External 2 years, 1 month
Bad String Format MASM External 2 years, 1 month
SuspendThread C++ External 2 years, 1 month
NLS Code Injection Through Registry C++ Unprotect 2 years, 1 month
Indicator Removal: Timestomp C Unprotect 2 years, 1 month
Killing Windows Event Log C++ Unprotect 2 years, 1 month

Filter