Stars
A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk
A reflective DLL development template for the Rust programming language
Prevent in-process process termination by patching exit APIs
A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.
A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.
Ridter / suo5
Forked from zema1/suo5一款高性能 HTTP 代理隧道工具 | A high-performance http proxy tunneling tool
LSASS Credential Dumper that utilizes the Windows API, in-memory RC4 encryption and Base64 encoding, and HTTPS exfiltration.
Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-mask-kit-iocs
An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.
gatariee / ScreenshotBOF
Forked from CodeXTF2/ScreenshotBOFAn alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.
Cobalt Strike random C2 Profile generator
Replace the .txt section of the current loaded modules from \KnownDlls\
NUL0x4C / libsodium
Forked from jedisct1/libsodiumA modern, portable, easy to use crypto library.
RunPE implementation with multiple evasive techniques
waldo-irc / GPUSleep
Forked from oXis/GPUSleepMove CS beacon to GPU memory when sleeping
A post exploitation framework designed to operate covertly on heavily monitored environments
Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence
This is the tool to dump the LSASS process on modern Windows 11