├── .gitattributes ├── .gitignore ├── AlertableThreadsForDays ├── AlertableThreadsForDays.cpp ├── AlertableThreadsForDays.vcxproj └── AlertableThreadsForDays.vcxproj.filters ├── CMakeLists.txt ├── ETWThreadCreationNoise └── FindRemoteThreadsETW.ps1 ├── LICENSE ├── README.md ├── RedirectThread.sln ├── RedirectThread ├── APCInjection.cpp ├── APCInjection.h ├── Arguments.cpp ├── Arguments.h ├── CreateRemoteThreadUtil h ├── CreateRemoteThreadUtil.cpp ├── DLLInjection.cpp ├── DLLInjection.h ├── GadgetUtil.cpp ├── GadgetUtil.h ├── Helpers.cpp ├── Helpers.h ├── Injection.cpp ├── Injection.h ├── NativeAPI.cpp ├── NativeAPI.h ├── NtCreateThreadUtil.cpp ├── NtCreateThreadUtil.h ├── ProcessThread.cpp ├── ProcessThread.h ├── RedirectThread.h ├── RedirectThread.vcxproj ├── RedirectThread.vcxproj.filters └── main.cpp └── ShellcodeExamples ├── sRDI-dll-cmd-shellcode.bin └── w10-x64-calc-shellcode-msfvenom.bin /.gitattributes: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/.gitattributes -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/.gitignore -------------------------------------------------------------------------------- /AlertableThreadsForDays/AlertableThreadsForDays.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/AlertableThreadsForDays/AlertableThreadsForDays.cpp -------------------------------------------------------------------------------- /AlertableThreadsForDays/AlertableThreadsForDays.vcxproj: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/AlertableThreadsForDays/AlertableThreadsForDays.vcxproj -------------------------------------------------------------------------------- /AlertableThreadsForDays/AlertableThreadsForDays.vcxproj.filters: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/AlertableThreadsForDays/AlertableThreadsForDays.vcxproj.filters -------------------------------------------------------------------------------- /CMakeLists.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/CMakeLists.txt -------------------------------------------------------------------------------- /ETWThreadCreationNoise/FindRemoteThreadsETW.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/ETWThreadCreationNoise/FindRemoteThreadsETW.ps1 -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/README.md -------------------------------------------------------------------------------- /RedirectThread.sln: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread.sln -------------------------------------------------------------------------------- /RedirectThread/APCInjection.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/APCInjection.cpp -------------------------------------------------------------------------------- /RedirectThread/APCInjection.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/APCInjection.h -------------------------------------------------------------------------------- /RedirectThread/Arguments.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Arguments.cpp -------------------------------------------------------------------------------- /RedirectThread/Arguments.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Arguments.h -------------------------------------------------------------------------------- /RedirectThread/CreateRemoteThreadUtil h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/CreateRemoteThreadUtil h -------------------------------------------------------------------------------- /RedirectThread/CreateRemoteThreadUtil.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/CreateRemoteThreadUtil.cpp -------------------------------------------------------------------------------- /RedirectThread/DLLInjection.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/DLLInjection.cpp -------------------------------------------------------------------------------- /RedirectThread/DLLInjection.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/DLLInjection.h -------------------------------------------------------------------------------- /RedirectThread/GadgetUtil.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/GadgetUtil.cpp -------------------------------------------------------------------------------- /RedirectThread/GadgetUtil.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/GadgetUtil.h -------------------------------------------------------------------------------- /RedirectThread/Helpers.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Helpers.cpp -------------------------------------------------------------------------------- /RedirectThread/Helpers.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Helpers.h -------------------------------------------------------------------------------- /RedirectThread/Injection.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Injection.cpp -------------------------------------------------------------------------------- /RedirectThread/Injection.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/Injection.h -------------------------------------------------------------------------------- /RedirectThread/NativeAPI.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/NativeAPI.cpp -------------------------------------------------------------------------------- /RedirectThread/NativeAPI.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/NativeAPI.h -------------------------------------------------------------------------------- /RedirectThread/NtCreateThreadUtil.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/NtCreateThreadUtil.cpp -------------------------------------------------------------------------------- /RedirectThread/NtCreateThreadUtil.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/NtCreateThreadUtil.h -------------------------------------------------------------------------------- /RedirectThread/ProcessThread.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/ProcessThread.cpp -------------------------------------------------------------------------------- /RedirectThread/ProcessThread.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/ProcessThread.h -------------------------------------------------------------------------------- /RedirectThread/RedirectThread.h: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/RedirectThread.h -------------------------------------------------------------------------------- /RedirectThread/RedirectThread.vcxproj: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/RedirectThread.vcxproj -------------------------------------------------------------------------------- /RedirectThread/RedirectThread.vcxproj.filters: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/RedirectThread.vcxproj.filters -------------------------------------------------------------------------------- /RedirectThread/main.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/RedirectThread/main.cpp -------------------------------------------------------------------------------- /ShellcodeExamples/sRDI-dll-cmd-shellcode.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/ShellcodeExamples/sRDI-dll-cmd-shellcode.bin -------------------------------------------------------------------------------- /ShellcodeExamples/w10-x64-calc-shellcode-msfvenom.bin: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Friends-Security/RedirectThread/HEAD/ShellcodeExamples/w10-x64-calc-shellcode-msfvenom.bin --------------------------------------------------------------------------------