Starred repositories
Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8
SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.
A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation
LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript
Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopefully…
Astral-PE is a low-level mutator (Headers/EP obfuscator) for native Windows PE files (x32/x64)
SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.
MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.
Pass the Hash to a named pipe for token Impersonation
Executes position independent shellcode from an encrypted zip
A standalone DLL that exports databases in cleartext once injected in the KeePass process.
Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domain joined machies
Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.
Obfuscate ECMA CIL (.NET IL) assemblies to evade Windows Defender AMSI
All my Source Codes (Repos) for Red-Teaming & Pentesting + Blue Teaming
Tool designed to find folder exclusions using Windows Defender using command line utility MpCmdRun.exe as a low privileged user, without relying on event logs
C# Implementation of the Hell's Gate VX Technique
Hide your P/Invoke signatures through other people's signed assemblies
comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules without Admin privileges
An App Domain Manager Injection DLL PoC on steroids
SharpSilentChrome is a C# project that "silently" installs browser extensions on Google Chrome or MS Edge by updating the browsers' Preferences and Secure Preferences files. Currently, it only supp…
Spoofing desktop login applications with WinForms and WPF