Skip to content
View tillstuder's full-sized avatar
:shipit:
:shipit:

Block or report tillstuder

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

90 stars written in C#
Clear filter

A method of bypassing EDR's active projection DLL's by preventing entry point exection

C# 1,156 163 Updated Mar 31, 2021

Spartacus DLL/COM Hijacking Toolkit

C# 1,066 154 Updated Feb 1, 2024

PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.

C# 1,051 148 Updated May 29, 2024

PowerShell rebuilt in C# for Red Teaming purposes

C# 1,037 144 Updated Nov 6, 2025

Framework for Kerberos relaying

C# 933 132 Updated May 29, 2022

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

C# 830 89 Updated Feb 3, 2024

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments

C# 830 112 Updated Dec 17, 2024

StandIn is a small .NET35/45 AD post-exploitation toolkit

C# 818 135 Updated Dec 2, 2023

Sandman is a NTP based backdoor for hardened networks.

C# 809 110 Updated Mar 31, 2024
C# 800 132 Updated Jun 1, 2023

SharpWMI is a C# implementation of various WMI functionality.

C# 763 140 Updated Jan 15, 2021

SMBeagle - Fileshare auditing tool.

C# 731 84 Updated Nov 4, 2025

C# Script used for Red Team

C# 724 140 Updated Nov 16, 2021

Self-developed tools for Lateral Movement/Code Execution

C# 717 143 Updated Aug 17, 2021

SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.

C# 667 131 Updated Feb 7, 2019

Original PoC for CVE-2023-32784

C# 646 58 Updated Aug 17, 2023

Get file less command execution for lateral movement.

C# 630 90 Updated Jun 3, 2022

Kusto Query Language is a simple and productive language for querying Big Data.

C# 630 117 Updated Nov 9, 2025

DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).

C# 558 81 Updated Jun 5, 2023

View ETW Provider manifest

C# 546 78 Updated Nov 1, 2024

it is very good

C# 517 69 Updated Dec 20, 2022

Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments.

C# 509 66 Updated Aug 7, 2024

C# tool for UAC bypasses

C# 445 55 Updated Aug 10, 2021

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

C# 438 43 Updated Aug 2, 2024
C# 417 40 Updated Apr 22, 2025

Dev Tunnels SDK

C# 411 33 Updated Oct 24, 2025

.NET Project for performing Authenticated Remote Execution

C# 405 69 Updated Feb 8, 2023

Self-hosted VirusTotal / MetaDefender wannabe with API, demo UI and Scanners running in Docker.

C# 368 49 Updated May 10, 2021

Abusing Azure services over C2

C# 364 34 Updated May 28, 2025