Skip to content
View 3v4Si0N's full-sized avatar
🏠
Working from home
🏠
Working from home

Highlights

  • Pro

Block or report 3v4Si0N

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
36 stars written in C#
Clear filter

A set of .NET libraries for Windows implementing PInvoke calls to many native Windows APIs with supporting wrappers.

C# 1,986 215 Updated Oct 17, 2025

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

C# 1,943 581 Updated Jul 20, 2021

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

C# 1,776 231 Updated Sep 4, 2024

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

C# 1,592 243 Updated Oct 11, 2018

PoCs and tools for investigation of Windows process execution techniques

C# 935 145 Updated Nov 4, 2025

Framework for Kerberos relaying

C# 933 132 Updated May 29, 2022

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

C# 862 127 Updated Mar 20, 2023

Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).

C# 805 129 Updated Dec 14, 2023

Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)

C# 796 162 Updated Feb 9, 2022

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

C# 765 113 Updated Dec 21, 2022

Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories, installed services and each service binaries metadata, inst…

C# 729 101 Updated Oct 28, 2025

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

C# 683 96 Updated May 7, 2025

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

C# 631 80 Updated Oct 18, 2025

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

C# 584 134 Updated Jan 31, 2020

PrintNotifyPotato

C# 529 65 Updated Dec 2, 2022

Excel Macro Document Reader/Writer for Red Teamers & Analysts

C# 524 79 Updated Feb 1, 2022

A .NET Framework 4.0 Windows Agent

C# 514 109 Updated Oct 29, 2025

A free and open-source .NET obfuscator using dnlib.

C# 514 79 Updated Aug 23, 2023

.NET/PowerShell/VBA Offensive Security Obfuscator

C# 510 109 Updated Feb 1, 2024

Tool to create hidden registry keys.

C# 489 96 Updated Oct 23, 2019

DeadPotato is a windows privilege escalation utility from the Potato family of exploits, leveraging the SeImpersonate right to obtain SYSTEM privileges. This script has been customized from the ori…

C# 444 48 Updated Aug 17, 2024

C# Reflective loader for unmanaged binaries.

C# 442 67 Updated Jan 25, 2023

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

C# 422 76 Updated Jul 27, 2022

LittleCorporal: A C# Automated Maldoc Generator

C# 231 60 Updated Jul 30, 2021

Weaponized HellsGate/SigFlip

C# 203 33 Updated Jun 7, 2023

A collection of weird ways to execute unmanaged code in .NET

C# 174 20 Updated May 4, 2021

Dump stuff without touching disk

C# 164 13 Updated Oct 29, 2020

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

C# 143 19 Updated Jul 11, 2020

C# version of MDSec's ParallelSyscalls

C# 141 24 Updated Jan 9, 2022

Companion PoC for the "Adventures in Dynamic Evasion" blog post

C# 123 20 Updated May 25, 2021
Next