Darkrain2009 / RedExtLinks
Chrome browser extension-based Command & Control
☆224Updated 5 months ago
Alternatives and similar repositories for RedExt
Users that are interested in RedExt are comparing it to the libraries listed below
Sorting:
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆181Updated 9 months ago
- Morpheus is an lsass stealer that extracts lsass.exe in RAM and exfiltrates it via forged and crypted NTP packets. For authorized testin…☆120Updated 6 months ago
- Havoc C2 profile generator☆100Updated 5 months ago
- NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into W…☆155Updated last year
- Evasive Golang Loader☆138Updated last year
- Webcam capture capability for Cobalt Strike as a BOF, with in-memory download options☆149Updated 9 months ago
- ☆198Updated 8 months ago
- Leverage WindowsApp createdump tool to obtain an lsass dump☆153Updated last year
- TeamServer and Client of Exploration Command and Control Framework☆174Updated last month
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆149Updated last year
- C or BOF file to extract WebKit master key to decrypt user cookie☆207Updated last year
- Port of Cobalt Strike's Process Inject Kit☆189Updated last year
- Abuse leaked token handles.☆134Updated 2 years ago
- A Mythic agent for Windows written in C☆142Updated this week
- AV bypass while you sip your Chai!☆226Updated last year
- Leak of any user's NetNTLM hash. Fixed in KB5040434☆257Updated last year
- Extracting NetNTLM without touching lsass.exe☆240Updated 2 years ago
- Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege☆224Updated 2 years ago
- Execute shellcode files with rundll32☆212Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆245Updated last week
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆212Updated last year
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆196Updated 8 months ago
- Terminate AV/EDR leveraging BYOVD attack☆102Updated 9 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆194Updated last year
- Collection of BOFs created for red team/adversary engagements. Created to be small and interchangeable, for quick recon or eventing.☆174Updated this week
- ☆221Updated last year
- PoC exploit for the vulnerable WatchDog Anti-Malware driver (amsdk.sys) – weaponized to kill protected EDR/AV processes via BYOVD.☆178Updated 3 months ago
- SOCKS5 proxy tool that uses Azure Blob Storage as a means of communication.☆258Updated 7 months ago
- Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation☆231Updated this week
- ☆163Updated 2 years ago