-
rpc2efs Public
Forked from Hypnoze57/rpc2efsUnauthenticated start EFS service on remote Windows host (make PetitPotam great again)
-
Havoc-C2-Modification-YARA-Free Public
Forked from JimKw1kX/Havoc-C2-Modification-YARA-FreePOC of modifying YARA signautre for Havoc C2
-
-
Pyramid Public
a tool to help operate in EDRs' blind spots
-
DojoLoader Public
Generic PE loader for fast prototyping evasion techniques
-
PythonMemoryModule Public
pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory
-
Packer_Development Public
Forked from rtecCyberSec/Packer_DevelopmentSlides & Code snippets for a workshop held @ x33fcon 2024
-
-
Embedder Public
Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies
-
krbdump Public
A way to extract tickets in case I need to purge and restore tickets on the fly.
-
krblist Public
Old post-ex for listing kerberos tickets. A terribly written clone of `klist`
-
grimreaper Public
Forked from RistBS/grimreaperA improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls
-
ProcessStomping Public
A variation of ProcessOverwriting to execute shellcode on an executable's section
-
ModuleShifting Public
Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes
-
GregsBestFriend Public
Forked from WKL-Sec/GregsBestFriendGregsBestFriend process injection code created from the White Knight Labs Offensive Development course
-
DropSpawn_BOF Public
Forked from Octoberfest7/DropSpawn_BOFCobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking
-
-
BouncyGate Public
Forked from eversinc33/BouncyGateHellsGate in Nim, but making sure that all syscalls go through NTDLL.DLL (as in RecycledGate).
-
UnhookingPatch Public
Forked from pdolinic/UnhookingPatchBypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime
-
GOAD Public
Forked from Orange-Cyberdefense/GOADgame of active directory
PowerShell GNU General Public License v3.0 UpdatedOct 7, 2022 -
Havoc Public
Forked from HavocFramework/HavocThe Havoc Framework
Go GNU General Public License v3.0 UpdatedOct 1, 2022 -
FilelessRemotePE Public
Forked from ASkyeye/FilelessRemotePELoading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique
-
DInjector Public
Forked from rvrsh3ll/DInjectorCollection of shellcode injection techniques packed in a D/Invoke weaponized DLL
-
TitanLdr Public
Forked from moonlight-junky/TitanLdrPublic variation of Titan Loader
-
FOLIAGE Public
Forked from moonlight-junky/FOLIAGEPublic variation of FOLIAGE ( original developer )
-
beacon Public
Forked from moonlight-junky/beaconFormer attempt at creating a independent Cobalt Strike Beacon
-
RWX-Dlls-for-manual-mapping Public
Forked from boom-cr3/RWX-Dlls-for-manual-mappingHere are a few rwx dlls your can use to manual map your cheat dll, they will prob get checked soon...
1 UpdatedMay 8, 2022 -
OffensivePipeline Public
Forked from snovvcrash/OffensivePipelineOffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.
-
python-bof-runner Public
Python inline shellcode injector that could be used to run BOFs by leveraging BOF2shellcode
-
DarkLoadLibrary Public
Forked from moloch--/DarkLoadLibraryLoadLibrary for offensive operations