Can't do exploitation research on a novel unhooking approach without a database of the DLLs for every Windows version. Ideas?

This page summarizes the projects mentioned and recommended in the original post on /r/lowlevel

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
  • introvert

  • I wrote about some weaknesses (this explains what this post is all about) I saw in this approach and reached out the the author of that 2017 Cylance whitepaper, Jeff Tang, who responded:

  • inline_syscall

    Inline syscalls made easy for windows on clang

  • https://github.com/JustasMasiulis/inline_syscall (AFAIK the only library that produces inline-able syscall stubs)

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • SysWhispers2

    AV/EDR evasion via direct system calls.

  • https://github.com/jthuraisamy/SysWhispers2 (one of the more recent infosec "inventions")

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts