Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View RemiEscourrou's full-sized avatar

Block or report RemiEscourrou

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
31 stars written in C
Clear filter

A little tool to play with Windows security

C 20,974 3,991 Updated May 11, 2025

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,189 2,993 Updated Nov 10, 2025

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

C 2,116 295 Updated Aug 15, 2024

The swiss army knife of LSASS dumping

C 2,025 256 Updated Sep 17, 2024

Situational Awareness commands implemented using Beacon Object Files

C 1,618 264 Updated Nov 10, 2025

HVNC for Cobalt Strike

C 1,283 198 Updated Dec 7, 2023

Cobalt Strike UDRL for memory scanner evasion.

C 985 169 Updated Jun 4, 2024

Windows System Explorer

C 870 164 Updated May 28, 2024

A .NET Runtime for Cobalt Strike's Beacon Object Files

C 754 109 Updated Sep 4, 2024

Execute unmanaged Windows executables in CobaltStrike Beacons

C 706 105 Updated Mar 4, 2023

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…

C 661 87 Updated Dec 23, 2022

Collection of Beacon Object Files (BOF) for Cobalt Strike

C 652 93 Updated Aug 15, 2025

Aims to identify sleeping beacons

C 635 60 Updated Dec 9, 2024

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

C 517 77 Updated Jun 10, 2025

Collection of remote authentication triggers in C#

C 514 61 Updated May 15, 2024

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C 505 58 Updated Mar 29, 2025

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

C 466 64 Updated Jul 6, 2024

UDRL for CS

C 443 68 Updated Dec 3, 2023

BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.

C 388 55 Updated Jan 9, 2024

A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC

C 371 57 Updated May 24, 2022

COFF file (BOF) for managing Kerberos tickets.

C 317 32 Updated Jul 2, 2023

Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.

C 312 47 Updated Jul 8, 2022

Cobalt Strike BOF for evasive .NET assembly execution

C 285 36 Updated Mar 31, 2025

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

C 284 37 Updated Jun 8, 2023

Print Spooler Named Pipe Impersonation for Cobalt Strike

C 270 39 Updated Jun 13, 2020

Zipper, a CobaltStrike file and folder compression utility.

C 225 49 Updated Jan 18, 2020

Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel

C 219 56 Updated Jul 14, 2021

Coerce Windows machines auth via MS-EVEN

C 168 16 Updated Jan 17, 2024
Next