Lists (1)
Sort Name ascending (A-Z)
Stars
A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
Portable Executable parsing library (from PE-bear)
A PowerShell variant of the amazing patch_review.py by kevthehermit
Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.
Centralized resource for listing and organizing known injection techniques and POCs
sud0Ru / CPLDCOMTrigger
Forked from klsecservices/CPLDCOMTriggerCPL remote trigger
A collection of various methods for adding user from windows
Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.
Threadless Process Injection using remote function hooking.
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
Shellcode and In-PowerShell solution for patching AMSI via Page Guard Exceptions
BOF for Kerberos abuse (an implementation of some important features of the Rubeus).
🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc
A list of useful Powershell scripts with 100% AV bypass (At the time of publication).
A Visual Studio template used to create Cobalt Strike BOFs
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.
Weaponize DLL hijacking easily. Backdoor any function in any DLL.