1-day current streak·5-day longest streak
Projects EyYoEtwWhereYouAt Proof of concept tool that monitors kernel events (image loads, process creation, thread creation) and identifies anomalous absences in corresponding ETW telemetry. When system activity occurs without expected…
Projects
EyYoEtwWhereYouAt
Proof of concept tool that monitors kernel events (image loads, process creation, thread creation) and identifies anomalous absences in corresponding ETW telemetry. When system activity occurs without expected ETW events, IE ETW Patching.cet-spoofing-detection
This tool is a proof of concept aimed to detect stackspoofing within CET processes. It does this by comparing the shadow stack to the userstack and looks for missing frames. Specifically targeting the modification of unwind data.SuspiciousThreads
A Poc attempt at hunting suspicious thread creation events using ETW only. it currently identifies- Unbacked Thread creation calls
- Unbacked StartAddress
- JOP based StartAddress
ModuleStomped
Proof of concept to detect module stomping detection by looking for modified .pdata sections.
-
EyYoEtwWhereYouAt ★ PINNED
Correlating kernel notifications with the lack of ETW events to detect ETW Patching
C++ ★ 7 4mo agoExplain → -
cet-spoofing-detection ★ PINNED
Stack spoofing Detection for CET processes by comparing shadow and user stacks.
C++ ★ 38 1mo agoExplain → -
SuspiciousThreads ★ PINNED
A Poc attempt at hunting suspicious thread creation events using ETW only.
C++ ★ 5 1mo agoExplain → -
ModuleStomped ★ PINNED
Proof of concept to detect module stomping detection by looking for modified .pdata sections.
C++ ★ 40 1mo agoExplain → -
vehspoof ▣
Callstack spoofing using a VEH because VEH all the things.
C ★ 24 1y agoExplain → -
taskpwn ▣
Remote Task Scheduler Enumeration
Python ★ 13 2y agoExplain → -
0xjbb
No description.
★ 1 1mo agoExplain → -
indirect-syscalls ▣
Indirect Syscall implementation, nothing new.
C ★ 1 2y agoExplain → -
0xjbb.github.io
Blog
★ 0 2y agoExplain →
No repos match these filters.