GitHub topics: runpe
adamhlt/Process-Hollowing
Process Hollowing in C++ (x86 / x64) - Process PE image replacement
Language: C++ - Size: 3.58 MB - Last synced at: 2 days ago - Pushed at: over 1 year ago - Stars: 145 - Forks: 31

DeAriasn/Simple-RunPE-Process-Hollowing
The RunPE program is written in C# to execute a specific executable file within another files memory using the ProcessHollowing technique.
Language: C# - Size: 49.8 KB - Last synced at: 4 days ago - Pushed at: 4 days ago - Stars: 0 - Forks: 0

TheNewAttacker64/Theattacker-Crypter
Tool to evade Antivirus With Different Techniques
Language: C# - Size: 11 MB - Last synced at: 13 days ago - Pushed at: over 1 year ago - Stars: 176 - Forks: 29

Kareasst/Simple-RunPE-Process-Hollowing
The RunPE program is written in C# to execute a specific executable file within another files memory using the ProcessHollowing technique.
Language: C# - Size: 221 KB - Last synced at: 17 days ago - Pushed at: 17 days ago - Stars: 2 - Forks: 0

DosX-dev/UPX-Patcher
Make "upx -d" unpacking impossible!
Language: Visual Basic .NET - Size: 413 KB - Last synced at: 15 days ago - Pushed at: about 1 year ago - Stars: 134 - Forks: 14

abdullah2993/go-runpe
execute a PE in the address space of another PE aka process hollowing
Language: Go - Size: 7.81 KB - Last synced at: 5 days ago - Pushed at: over 3 years ago - Stars: 55 - Forks: 19

XaFF-XaFF/ZwProcessHollowing
ZwProcessHollowing is a x64 process hollowing project which uses direct systemcalls, dll unhooking and RC4 payload decryption
Language: C++ - Size: 13.7 KB - Last synced at: 19 days ago - Pushed at: about 2 years ago - Stars: 84 - Forks: 21

itm4n/VBA-RunPE 📦
A VBA implementation of the RunPE technique or how to bypass application whitelisting.
Language: VBA - Size: 5.36 MB - Last synced at: 19 days ago - Pushed at: over 5 years ago - Stars: 801 - Forks: 179

hasherezade/chimera_pe
ChimeraPE (a PE injector type - alternative to: RunPE, ReflectiveLoader, etc) - a template for manual loading of EXE, loading imports payload-side
Language: C - Size: 231 KB - Last synced at: 11 days ago - Pushed at: about 2 years ago - Stars: 220 - Forks: 58

Tastortist/Simple-RunPE-Process-Hollowing
The RunPE program is written in C# to execute a specific executable file within another files memory using the ProcessHollowing technique.
Language: C# - Size: 229 KB - Last synced at: about 1 month ago - Pushed at: about 1 month ago - Stars: 2 - Forks: 0

hasherezade/demos
Demos of various injection techniques found in malware
Language: C - Size: 217 KB - Last synced at: 17 days ago - Pushed at: about 3 years ago - Stars: 792 - Forks: 183

IntelSDM/PEFromMemory
Executing EXE Files From Memory
Language: C++ - Size: 9.77 KB - Last synced at: 1 day ago - Pushed at: over 1 year ago - Stars: 12 - Forks: 2

EducationaSites/UniversalCrypter
Best Free Open Source FUD Crypter
Size: 1000 Bytes - Last synced at: about 2 months ago - Pushed at: about 2 months ago - Stars: 0 - Forks: 0

NYAN-x-CAT/CSharp-RunPE
Hide malware behind a legit process C#
Language: C# - Size: 7.81 KB - Last synced at: 5 days ago - Pushed at: about 5 years ago - Stars: 118 - Forks: 39

K3rnel-Dev/RunPE-Builder
Demo work of injection into someone else's address space process
Language: C# - Size: 1.5 MB - Last synced at: about 1 month ago - Pushed at: 4 months ago - Stars: 0 - Forks: 1

TRDropperGen/Runpe-Process-Hollowing-Shellcode
process hollowing shellcode
Language: Visual Basic 6.0 - Size: 24.4 KB - Last synced at: 11 days ago - Pushed at: 2 months ago - Stars: 2 - Forks: 0

Evi1Grey5/Loader
The most common techniques to this day are RunPE and LoadPE 👨💻
Language: C - Size: 236 KB - Last synced at: 2 months ago - Pushed at: 2 months ago - Stars: 8 - Forks: 2

UniversDevs/UniversalCrypter
Best Free Open Source FUD Crypter
Language: Visual Basic .NET - Size: 1.03 MB - Last synced at: 3 months ago - Pushed at: 3 months ago - Stars: 1 - Forks: 0

comradecollin/Crypter-FUD-STUB-Bypass-Windows-Defender
Crypter / Packer bypassing windows defender as of release. Working with x64 exe files.
Size: 38.1 KB - Last synced at: 5 months ago - Pushed at: 5 months ago - Stars: 1 - Forks: 0

Siysyter/Simple-RunPE-Process-Hollowing
The RunPE program is written in C# to execute a specific executable file within another files memory using the ProcessHollowing technique.
Language: C# - Size: 1 MB - Last synced at: 7 months ago - Pushed at: 7 months ago - Stars: 4 - Forks: 0

Paskowsky/DreamProtectorFree
Simple protector to show how to run a payload without dropping it using RunPE Technique
Language: C# - Size: 264 KB - Last synced at: 4 months ago - Pushed at: almost 8 years ago - Stars: 35 - Forks: 22

mm-rezaei/ProcessHollowing3
Implementation of the Process Hollowing technique for process injection (This is the third of three methods in the series)
Language: C++ - Size: 170 KB - Last synced at: 8 months ago - Pushed at: 8 months ago - Stars: 0 - Forks: 0

mm-rezaei/ProcessHollowing2
Implementation of the Process Hollowing technique for process injection (This is the second of three methods in the series)
Language: C++ - Size: 164 KB - Last synced at: 8 months ago - Pushed at: 8 months ago - Stars: 0 - Forks: 0

mm-rezaei/ProcessHollowing1
Implementation of the Process Hollowing technique for process injection (This is the first of three methods in the series)
Language: C++ - Size: 167 KB - Last synced at: 8 months ago - Pushed at: 8 months ago - Stars: 0 - Forks: 0

itaymigdal/PichichiH0ll0wer
Nim process hollowing loader
Language: Nim - Size: 2.56 MB - Last synced at: 9 months ago - Pushed at: 9 months ago - Stars: 46 - Forks: 11

NetherB3n/IvanCrypt-Crypter
A simple crypter/packer that is currently bypassing windows defender
Size: 1.95 KB - Last synced at: 11 months ago - Pushed at: 11 months ago - Stars: 2 - Forks: 0

Raupo1984/Fud-Crypter-2024-Olympos-Builder
Fullyundedectable Runtime Crypter Services
Language: C# - Size: 43 KB - Last synced at: 12 months ago - Pushed at: 12 months ago - Stars: 2 - Forks: 0

Chainski/Chainski-Crypter Fork of NYAN-x-CAT/Lime-Crypter
Lime Crypter Obfuscator Mod
Language: C# - Size: 4.99 MB - Last synced at: 12 months ago - Pushed at: 12 months ago - Stars: 23 - Forks: 6

Sty1x/Fud-Crypter-2024-Styx-Builder
Legal and Effective: Styx FUD Crypter for Software Protection
Language: C# - Size: 36.1 KB - Last synced at: 12 months ago - Pushed at: 12 months ago - Stars: 217 - Forks: 0

TalosSec/Cronos-Crypter
Cronos Crypter is an simple example of crypter created for educational purposes.
Language: C# - Size: 148 KB - Last synced at: 12 months ago - Pushed at: almost 3 years ago - Stars: 92 - Forks: 26

aaaddress1/RunPE-In-Memory
Run a Exe File (PE Module) in memory (like an Application Loader)
Language: C++ - Size: 40.9 MB - Last synced at: about 1 year ago - Pushed at: about 4 years ago - Stars: 773 - Forks: 160

DevinAIDeveloper/DevinPE-ProcessHollowing-Example
DevinPE-ProcessHollowing-Example
Language: C# - Size: 34.2 KB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 0 - Forks: 0

UniversDevz/UniversalCrypter
Best Free Open Source Crypter
Language: Visual Basic .NET - Size: 882 KB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 0 - Forks: 0

BelodedAleksey/go_libpeconv
Golang version of https://github.com/hasherezade/libpeconv
Language: Go - Size: 12.4 MB - Last synced at: about 1 year ago - Pushed at: about 5 years ago - Stars: 25 - Forks: 5

DigiDonkz/TheCrypter
Web-based Polymorphic Runtime Crypter FUD
Size: 760 KB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 2 - Forks: 0

Shinyenigma/XWorm-RAT
A famous XWorm RAT. ✨The price is 20$✨All the popular RAT options, please read the description
Size: 19.5 KB - Last synced at: over 1 year ago - Pushed at: over 1 year ago - Stars: 23 - Forks: 3

jusyac/XWorm-RAT
A famous XWorm RAT. All the popular RAT options
Size: 938 KB - Last synced at: over 1 year ago - Pushed at: over 1 year ago - Stars: 0 - Forks: 0

naksyn/PythonMemoryModule
pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory
Language: Python - Size: 1.16 MB - Last synced at: over 1 year ago - Pushed at: over 1 year ago - Stars: 265 - Forks: 79

Shinyenigma/Venom-RAT-V6.0.3
The well-known Venom RAT, latest version built from the original source code (NOT A CRACK). ✨The price is 20$✨More info in the description
Size: 4.88 KB - Last synced at: over 1 year ago - Pushed at: over 1 year ago - Stars: 6 - Forks: 2

iceMANkingg/CRAX-Crypter-By-IceMan
CRAX Crypter By IceMan
Size: 2.93 KB - Last synced at: almost 2 years ago - Pushed at: almost 2 years ago - Stars: 1 - Forks: 0

CodiumAlgorithm/-Delphi-Process-Hollowing-RunPE-by-Jean-Pierre-LESUEUR
Delphi Process Hollowing, Updated.
Language: Pascal - Size: 4.88 KB - Last synced at: almost 2 years ago - Pushed at: almost 3 years ago - Stars: 6 - Forks: 1

TheKevinWang/HellsRunPE
RunPE using Hell's Gate technique.
Language: C - Size: 21.5 KB - Last synced at: almost 2 years ago - Pushed at: over 4 years ago - Stars: 22 - Forks: 7

hidd3ncod3s/runpedmp
RunPE dump - I wrote this to have better control over the analysis of malwares. I can stop and analysis malware when it uses some of the API's i hook and to dump the memory while it is using RunPE/PH techniques.
Language: C++ - Size: 121 KB - Last synced at: about 2 years ago - Pushed at: almost 10 years ago - Stars: 10 - Forks: 10

ivkin25/Process-Hollowing
An implementation of the Process Hollowing technique.
Language: C++ - Size: 88.9 KB - Last synced at: about 2 years ago - Pushed at: over 4 years ago - Stars: 11 - Forks: 5

1M50RRY/runpe-native-loader
Loader and RunPE file executer
Language: C++ - Size: 16.6 KB - Last synced at: about 2 years ago - Pushed at: almost 6 years ago - Stars: 12 - Forks: 18

hidd3ncod3s/PackerAttacker Fork of BromiumLabs/PackerAttacker
C++ application that uses memory and code hooks to detect packers
Language: C++ - Size: 105 KB - Last synced at: about 2 years ago - Pushed at: about 9 years ago - Stars: 1 - Forks: 0
