Cobalt-Strike / obfuscator-llvm
☆47Updated last year
Alternatives and similar repositories for obfuscator-llvm:
Users that are interested in obfuscator-llvm are comparing it to the libraries listed below
- A work in progress BOF/COFF loader in Rust☆47Updated 2 years ago
- ☆23Updated this week
- Sliver agent rewritten in C++☆44Updated 6 months ago
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆43Updated 2 years ago
- Beacon Debugger☆40Updated 4 months ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆101Updated 2 years ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆43Updated last year
- Artemis - C++ Hell's Gate Syscall Implementation☆32Updated last year
- Beacon Object Files (not Buffer Overflows)☆53Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year
- yet another sleep encryption thing. also used the default github repo name for this one.☆70Updated last year
- ☆98Updated last year
- Repo that holds random POCs☆49Updated last year
- ☆47Updated 2 years ago
- Sleep Obfuscation☆43Updated 2 years ago
- ☆25Updated 2 months ago
- A VSCode plugin to assist with BOF development.☆34Updated 7 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆24Updated 6 months ago
- Execute dotnet app from unmanaged process☆71Updated 2 months ago
- BypassCredGuard CS BOF☆32Updated 2 months ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆83Updated 2 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆52Updated last year
- Windows x64 Process Injection via Ghostwriting with Dynamic Configuration☆29Updated 3 years ago
- ☆28Updated 9 months ago
- I have documented all of the AMSI patches that I learned till now☆74Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆62Updated last year
- ☆52Updated 2 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆48Updated last year
- Windows C++ Implant for Exploration C2☆28Updated last week
- EmbedExeLnk by x86matthew modified by d4rkiZ☆35Updated last year