0xrawsec / golang-etw
☆35Updated 2 years ago
Alternatives and similar repositories for golang-etw:
Users that are interested in golang-etw are comparing it to the libraries listed below
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆61Updated 8 months ago
- Go implementation of the Heaven's Gate technique☆96Updated 3 years ago
- Lists of AMSI triggers (VBA, JScript / VBScript)☆32Updated 5 years ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- A PoC package for hosting the CLR and executing .NET from Go☆68Updated 6 months ago
- Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.☆112Updated 3 years ago
- Simple windows rpc server for research purposes only☆82Updated 2 years ago
- PoC to interact with local/remote registry hives through WMI☆84Updated 4 years ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆61Updated last year
- ☆36Updated 4 years ago
- Reflectively load PE☆102Updated 4 years ago
- golang implementation of Syswhisper2/Syswhisper3☆23Updated 2 years ago
- Golang evasion tool, execute-assembly .Net file☆94Updated 2 years ago
- nuke that event log using some epic dinvoke fu☆116Updated 3 years ago
- Utility for hunting UAC bypasses or COM/DLL hijacks that alerts on the exported function that was consumed.☆41Updated last year
- ☆66Updated 3 years ago
- This contains a number of examples demonstrating how to use callback functions in supported aggressor script functions☆30Updated 6 months ago
- Dump Citrix Secure Access auth cookie from the process memory☆72Updated 2 years ago
- Repo that holds random POCs☆48Updated last year
- MacOS C2 Framework☆82Updated 3 years ago
- ☆56Updated 3 years ago
- Simple PoCs for utilizing Windows syscalls in Go☆15Updated 4 years ago
- Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs☆120Updated 2 years ago
- ☆141Updated 2 years ago
- x64 version☆30Updated 3 years ago
- Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.☆41Updated last year
- ☆50Updated 4 years ago
- ☆42Updated 2 years ago
- Kerberos laboratory to better understand and then detecting attack on kerberos☆67Updated 3 years ago
- ☆80Updated 2 years ago