Machinegun
Nidhogg
Machinegun | Nidhogg | |
---|---|---|
1 | 9 | |
2 | 1,622 | |
- | - | |
10.0 | 8.1 | |
about 1 year ago | about 1 month ago | |
C++ | C++ | |
BSD 2-clause "Simplified" License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Machinegun
Nidhogg
-
Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.
This is not an exploit nor an example about how to write a driver and I didn't write anywhere about an exploit or how to write an driver. If you are looking for these kind of resources, feel free to check out my driver programming blog series "Lord of the Ring0" (and a talk that will be released soon! :) ): https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html
- Release Version 0.4 Release - Nidhogg - The goal of Nidhogg is to provide an all-in-one and easy-to-use rootkit with multiple helpful functionalities for red team engagements that can be integrated with your C2 framework via a single header file - this version introduced various new capabilities
- Nidhogg: Nidhogg is an all-in-one simple to use rootkit for red teams.
-
Lord Of The Ring0 (Part 2) - Lessons Learned Developing the Nidhogg Rootkit
Part 1
- Nidhogg: Nidhogg is an all-in-one simple to use rootkit for red teams. Nidhogg can work on any version of Windows 10 and Windows 11.
- Nidhogg: Nidhogg is an all-in-one simple to use rootkit for red teams. Nidhogg can work on any version of Windows 10 and Windows 11. - in reality this is a userland implant
- Nidhogg rootkit - An all in one rootkit for all windows 10 versions and windows 11 that can be managed with single hpp file
What are some alternatives?
Amsi-Killer - Lifetime AMSI bypass
Cronos-Rootkit - Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
Cronos - PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.
PowerShell-Red-Team - Collection of PowerShell functions a Red Teamer may use in an engagement
Jormungandr - Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.
Sandman - Sandman is a NTP based backdoor for red team engagements in hardened networks.
flutter_native_view - [WIP] Embedding native windows into Flutter. Scrollable support & widgets placement on-top. 🪟
Inline-Execute-PE - Execute unmanaged Windows executables in CobaltStrike Beacons
Venom - Venom is a library that meant to perform evasive communication using stolen browser socket
boom-os - This is an x64 OS barely at development stages with hobbyist goals
WinAPI-RedBlue - Source code of exploiting windows API for red teaming series
CVE-2020-15368 - CVE-2020-15368, aka "How to exploit a vulnerable driver"