Stars
Windows protocol library, including SMB and RPC implementations, among others.
WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API
Decrypt GlobalProtect configuration and cookie files.
Tools for interacting with authentication packages using their individual message protocols
A set of fully-undetectable process injection techniques abusing Windows Thread Pools
A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.
An example MS-W32T client to show how to use midl.exe in a project managed by CMake
Load a dynamic library from memory by modifying the native Windows loader
A modern 32/64-bit position independent implant template
Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations
Python library for using asyncio in Qt-based applications.
BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs
A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
Simple (relatively) things allowing you to dig a bit deeper than usual.
Situational Awareness commands implemented using Beacon Object Files
Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (AC…
Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)
Provides a simple framework for writing line-oriented command interpreters in C#. Inspired by the Python cmd library.
A way to delete a locked file, or current running executable, on disk.
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers, Unlinking .NET related modules, bypassing ETW+AMSI, avo…
Cobalt Strike Malleable C2 Design and Reference Guide
Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)