CERTCC / privesc
Process Monitor filter for finding privilege escalation vulnerabilities on Windows
☆78Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for privesc
- ☆54Updated 3 years ago
- Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process☆97Updated last year
- AMSI Bypass Via the Heap☆105Updated 4 years ago
- A small project to bypass UAC in windows 10/8/7 using dll injection technique☆73Updated 4 years ago
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆121Updated 3 years ago
- A BOF to interact with COM objects associated with the Windows software firewall.☆100Updated 3 years ago
- .NET project for installing Persistence☆64Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆65Updated 4 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- Windows internals and exploitation tricks☆92Updated 5 months ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆88Updated last year
- Tradecraft Development Fundamentals☆40Updated 3 years ago
- DInvisibleRegistry☆81Updated 4 years ago
- ☆41Updated 2 years ago
- Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR☆97Updated 3 years ago
- The repository that complements the From zero to hero: creating a reflective loader in C# workshop☆38Updated 3 years ago
- subTee gists code backups☆37Updated 6 years ago
- OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.☆90Updated 2 years ago
- A fake AMSI Provider which can be used for persistence.☆139Updated 3 years ago
- ☆51Updated 3 years ago
- Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.☆97Updated 2 years ago
- ☆38Updated 2 years ago
- ☆69Updated 3 years ago
- Tool for interacting with outlook interop during red team engagements☆144Updated 3 years ago
- Grab Firefox post requests by hooking PR_Write function from nss3.dll module using trampoline hook to get passwords and emails of users☆42Updated 2 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago