Reattempt of BlueHammer disclosed in April 2026
β68May 11, 2026Updated 3 months ago
Alternatives and similar repositories for BlueHammer
Users that are interested in BlueHammer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Native Bash Framework for Kerberos Ticket Extraction on Linux πβ48Feb 23, 2026Updated 6 months ago
- β41Nov 25, 2025Updated 9 months ago
- Performs a global AMSI bypass by patching amsi.dll in memory.β20Oct 14, 2025Updated 10 months ago
- Analysis and detection engineering for the BlueHammer Windows Defender local privilege escalation vulnerability. This repo includes bug fβ¦β97Apr 8, 2026Updated 4 months ago
- A Crystal Palace shared library to resolve & perform syscallsβ66Oct 29, 2025Updated 9 months ago
- Managed Kubernetes at scale on DigitalOcean β’ AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- An example UDC2 implementation for CrystalC2.β19Jun 19, 2026Updated 2 months ago
- A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itselfβ100Apr 9, 2026Updated 4 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.β23Nov 11, 2025Updated 9 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.β167Apr 15, 2026Updated 4 months ago
- rust port of pspy with support for process monitoring over dbusβ39Jan 4, 2026Updated 7 months ago
- A hacky way of getting cross-arch/platform support in Cobalt Strikeβ39Aug 31, 2025Updated 11 months ago
- A newly discovered vulnerable driver, pstrip64.sys (CVE-2026-29923) allows an unprivileged user to escalate privileges to SYSTEM via a crβ¦β25Apr 11, 2026Updated 4 months ago
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistenceβ65Jun 23, 2025Updated last year
- Command Augmentation support for BOFs and .NET assemblies across agentsβ50Jul 30, 2026Updated 3 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- NSecSoftBYOVD POCβ62Feb 12, 2026Updated 6 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.β76Aug 24, 2025Updated last year
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.β17Dec 29, 2022Updated 3 years ago
- Reimplementing Havoc Pro Runtime Channel Switching and Cobalt Strike UDC2 features.β51Aug 16, 2026Updated last week
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.β40Apr 6, 2026Updated 4 months ago
- Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browserβ¦β262May 18, 2026Updated 3 months ago
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.β62Feb 25, 2025Updated last year
- Kassandra is a custom Mythic C2 agent written in Rust, containerized via a Python-based builderβ24Jul 31, 2026Updated 3 weeks ago
- A modern alternative Web-UI for the Mythic Command and Control Serverβ83Jul 3, 2026Updated last month
- GPU virtual machines on DigitalOcean Gradient AI β’ AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- WebClientRelayUp - an universal no-fix local privilege escalation in domain-joined windows workstations in default configuration.β86Apr 28, 2026Updated 3 months ago
- Terms of Use Conditional Access M365 Evilginx Phishletβ47Jun 23, 2025Updated last year
- BOF POC of the DSCourier project / invoking WinGet via COMβ90Apr 23, 2026Updated 4 months ago
- A different approach to writing BOFs in rust.β21Aug 20, 2025Updated last year
- Lnk crafting and research toolsβ185Mar 4, 2026Updated 5 months ago
- CVE-2020-17103 adapted for C2 with split-binary SYSTEM callbackβ45May 20, 2026Updated 3 months ago
- β18Dec 11, 2025Updated 8 months ago
- Mentally ill EtwTi parserβ73Jan 11, 2026Updated 7 months ago
- β29Apr 5, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- β15Jan 15, 2026Updated 7 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+Sβ¦β119Dec 21, 2025Updated 8 months ago
- Async BOF to monitor and detect clipboard changes on a target system and return the clipboard contents.β22Jul 23, 2026Updated last month
- Adaptix C2 agent using Crystal Palace PIC linker and PICO module systemβ114Jun 7, 2026Updated 2 months ago
- β22Jun 24, 2025Updated last year
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.β63May 4, 2026Updated 3 months ago
- Surgical UNWIND_INFO preservation for sleep masking without call stack spoofing.β55Mar 30, 2026Updated 4 months ago