CodeXTF2 / WindowSpyLinks
WindowSpy is a Cobalt Strike Beacon Object File meant for automated and targeted user surveillance.
☆281Updated 10 months ago
Alternatives and similar repositories for WindowSpy
Users that are interested in WindowSpy are comparing it to the libraries listed below
Sorting:
- A shellcode injection tool showcasing various process injection techniques☆136Updated 2 years ago
- RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++☆259Updated 2 years ago
- NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into W…☆155Updated last year
- ☆169Updated last year
- Evasive Golang Loader☆137Updated last year
- A collection of Cobalt Strike Aggressor scripts.☆106Updated 4 years ago
- Execute shellcode from a remote-hosted bin file using Winhttp.☆240Updated 2 years ago
- Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles☆202Updated last year
- Set of python scripts which perform different ways of command execution via WMI protocol.☆164Updated 2 years ago
- AV bypass while you sip your Chai!☆227Updated last year
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆309Updated 2 years ago
- Documents Exfiltration project for fun and educational purposes☆144Updated 2 years ago
- 🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.☆158Updated 2 years ago
- Patching AmsiOpenSession by forcing an error branching☆153Updated 2 years ago
- Execute shellcode files with rundll32☆214Updated last year
- Github as C2 Demonstration , free API = free C2 Infrastructure☆144Updated 2 years ago
- Collection of random RedTeam scripts.☆211Updated last year
- Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.☆311Updated 3 years ago
- ☆247Updated 3 years ago
- ☆163Updated 2 years ago
- 「💀」Proof of concept on BYOVD attack☆165Updated last year
- Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC☆176Updated 3 years ago
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆302Updated 3 years ago
- ☆222Updated last year
- PowerShell runner for executing malicious payloads in order to bypass Windows Defender.☆72Updated 4 years ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆543Updated last month
- A keystroke logger targeting the Remote Desktop Protocol (RDP) related processes, It utilizes a low-level keyboard input hook, allowing i…☆396Updated 2 years ago
- yet another AV killer tool using BYOVD☆300Updated 2 years ago
- All my Source Codes (Repos) for Red-Teaming & Pentesting + Blue Teaming☆235Updated last year
- Modules used by the Havoc Framework☆256Updated last year