Skip to content
View bytecode77's full-sized avatar
🤔
return to libc
🤔
return to libc

Block or report bytecode77

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bytecode77/README.md

r77 Rootkit

Fileless ring 3 rootkit

  • Hides processes, files, network connections, etc.
  • Out of the box, single file installer
  • Fileless persistence, in-memory injection


PEunion

Crypter, binder & downloader

  • In-memory decryption & execution
  • Two-layer execution architecture


Living Off The Land

State of the art fileless attacks

  • Execution without any files
  • Process injection
  • Persistence

... It's technically not even there

Pinned Loading

  1. r77-rootkit r77-rootkit Public

    Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

    C 1.7k 400

  2. pe-union pe-union Public

    Crypter, binder & downloader with native & .NET stub, evasive by design, user friendly UI

    Assembly 649 145

  3. living-off-the-land living-off-the-land Public

    Fileless attack with persistence

    C++ 333 57

  4. slui-file-handler-hijack-privilege-escalation slui-file-handler-hijack-privilege-escalation Public

    Slui File Handler Hijack UAC Bypass Local Privilege Escalation

    C++ 89 33

  5. self-morphing-csharp-binary self-morphing-csharp-binary Public

    Executable that mutates its own code

    C# 369 105

  6. bytecode-api bytecode-api Public

    Framework for C# development

    C# 70 21