Skip to content
#

usermode

Here are 38 public repositories matching this topic...

Complete Windows usermode rootkit with custom C2 server, dropper, and EDR bypass. Features: privilege escalation, process/file/registry hiding, keylogger, reverse shell. Evasion: indirect syscalls, NTDLL unhooking, API hashing, ETW/AMSI bypass.

  • Updated Dec 19, 2025
  • Python

Improve this page

Add a description, image, and links to the usermode topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the usermode topic, visit your repo's landing page and select "manage topics."

Learn more