☆58Jul 12, 2026Updated 3 weeks ago
Alternatives and similar repositories for COMLoaderAstharot
Users that are interested in COMLoaderAstharot are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- DynLoader A modular Windows loader focused on EDR evasion Built with indirect syscall (Tartarus Gate / Hell’s Gate), Manual PE parsing …☆81Jul 10, 2026Updated 3 weeks ago
- BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.☆112Jul 14, 2026Updated 2 weeks ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated last week
- ☆68Jul 14, 2026Updated 2 weeks ago
- Evasive loader for .NET Framework assemblies☆45May 14, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated last month
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 3 months ago
- ☆88Apr 8, 2026Updated 3 months ago
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 4 months ago
- Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijac…☆136Jul 20, 2026Updated 2 weeks ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆114Jun 30, 2026Updated last month
- Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering resu…☆94Jul 27, 2026Updated last week
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 6 months ago
- ☆97Updated this week
- WinMan - An Offline WIN/NT API Documentation☆30Jul 8, 2026Updated 3 weeks ago
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆44Jun 8, 2026Updated last month
- A EDR bypassing shellcode loader framework for Windows 10 64bit, featuring ETW/AMSI patching, Tartarus Gate, process protection and more☆92Jun 24, 2026Updated last month
- Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled T…☆128Jan 24, 2026Updated 6 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆34Mar 20, 2023Updated 3 years ago
- sigreturn-oriented(SROP) based sleep obfuscation poc for Linux☆69Dec 15, 2025Updated 7 months ago
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆96Mar 29, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.☆75Jun 24, 2026Updated last month
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 3 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 3 months ago
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆105Jun 24, 2026Updated last month
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 3 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆280Jun 22, 2026Updated last month
- Just another EDR killer☆141Jan 21, 2026Updated 6 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last week
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 6 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆57Jul 4, 2026Updated 3 weeks ago
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆95Mar 7, 2026Updated 4 months ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆40Jul 23, 2026Updated last week
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago