Skip to content
View cowbe0x004's full-sized avatar

Block or report cowbe0x004

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
20 results for sponsorable starred repositories written in C#
Clear filter

Open source obfuscation tool for .NET assemblies

C# 2,895 436 Updated May 12, 2025

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

C# 1,776 231 Updated Sep 4, 2024

Phone Link / KDE Connect alternative

C# 1,651 26 Updated Nov 2, 2025

Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities

C# 1,644 273 Updated Nov 28, 2020

A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.

C# 1,354 468 Updated Jul 27, 2025

A method of bypassing EDR's active projection DLL's by preventing entry point exection

C# 1,155 163 Updated Mar 31, 2021

Also known by Microsoft as Knifecoat 🌶️

C# 1,146 207 Updated Dec 22, 2022

Hunts out CobaltStrike beacons and logs operator command output

C# 948 111 Updated Sep 4, 2024

StandIn is a small .NET35/45 AD post-exploitation toolkit

C# 816 135 Updated Dec 2, 2023

C# Script used for Red Team

C# 724 140 Updated Nov 16, 2021

Self-developed tools for Lateral Movement/Code Execution

C# 717 143 Updated Aug 17, 2021

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

C# 683 96 Updated May 7, 2025

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!

C# 515 55 Updated May 9, 2025

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

C# 424 76 Updated Sep 1, 2024

Pass the Hash to a named pipe for token Impersonation

C# 310 53 Updated Nov 29, 2023

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality

C# 288 45 Updated Jun 26, 2023

Run shellcode from resource

C# 260 65 Updated Dec 13, 2020
C# 162 13 Updated Jan 27, 2025

Port of Invoke-Excel4DCOM

C# 104 19 Updated Oct 12, 2019

Example code samples from our ScriptBlock Smuggling Blog post

C# 91 13 Updated Jun 18, 2024