C5Hackr / ARM64_AmsiPatchLinks
☆18Updated 2 months ago
Alternatives and similar repositories for ARM64_AmsiPatch
Users that are interested in ARM64_AmsiPatch are comparing it to the libraries listed below
Sorting:
- single-threaded event driven sleep obfuscation poc for linux☆34Updated last month
- Extension functionality for the NightHawk operator client☆27Updated last year
- A simple rpc2socks alternative in pure Go.☆28Updated last year
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- Golang Implementation of Hell's gate☆17Updated 2 years ago
- ☆18Updated 6 months ago
- Cobalt Strike notifications via NTFY.☆14Updated 9 months ago
- Just another Process Injection using Process Hollowing technique.☆17Updated last year
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆20Updated last year
- Watches the Downloads folder for any new files and inserts it into Nemesis for analysis.☆14Updated last year
- A tool to enumerate and download files from the System Center Configuration Manager (SCCM) SMB share (SCCMContentLib)☆13Updated 11 months ago
- string encryption in Nim☆20Updated last year
- Ludus role for deploying a Mythic Teamserver onto Linux servers☆14Updated 4 months ago
- A simple to use single-include Windows API resolver☆22Updated last year
- Nemesis agent for Mythic☆27Updated 10 months ago
- The Totally Legit Authentication Dialog☆12Updated last year
- Create PDFs with HTML smuggling attachments that save on opening the document.☆30Updated 2 weeks ago
- Automated (kinda) deployment of MalRDP infrastructure with Terraform & Ansible☆12Updated last year
- Unix Process hollowing in rust☆22Updated 7 months ago
- Mythic C2 wrapper for NimSyscallPacker☆25Updated 4 months ago
- Command and Control Framework using powershell implants☆35Updated 3 weeks ago
- ☆16Updated last year
- Smuggle a file to a user's browser☆20Updated 3 years ago
- An improvement and a different approach to Mockingjay Self-Injection.☆35Updated last year
- Deobfuscation of XorStringsNet☆14Updated 8 months ago
- Identify binaries with Authenticode digital signatures signed to an internal CA/domain☆40Updated last year
- A .NET 4.8 application to retrieve delivr.to emails from Microsoft Outlook via COM☆20Updated last year
- ☆26Updated 4 months ago
- Items related to the RedELK workshop given at security conferences☆29Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆43Updated 11 months ago