Category: Post Exploitation

HookDump: EDR function hook dumping

HookDump EDR function hook dumping. Hook Types Detected JMP A jump instruction has been patched into the function to redirect execution flow WOW Detection of the WOW64 syscall stub being hooked, which allows filtering...

Lateral Movement

CheeseTools: Lateral Movement/Code Execution

CheeseTools This repository has been made basing onto the already existing MiscTool, so big shout-out to rasta-mouse for releasing them and for giving me the right motivation to work on them. CheeseExec Command Exec / Lateral movement...