Elmofire / efLinks
Yet another obfuscated payload generator written in Rust!
☆13Updated 3 years ago
Alternatives and similar repositories for ef
Users that are interested in ef are comparing it to the libraries listed below
Sorting:
- Slides & Code snippets for a workshop held @ x33fcon 2024☆282Updated last year
- Apply a divide and conquer approach to bypass EDRs☆288Updated 2 years ago
- Template-based shellcode packer written in Rust, with indirect syscall support. Made with <3 for pentesters.☆317Updated 7 months ago
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆129Updated 2 years ago
- Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST☆197Updated last year
- Using fibers to run in-memory code.☆240Updated 2 years ago
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆212Updated last year
- ☆290Updated 2 years ago
- Open Source C&C Specification☆278Updated 11 months ago
- A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and …☆191Updated 9 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-bui…☆231Updated 11 months ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆202Updated 10 months ago
- ☆246Updated last year
- Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)☆259Updated last year
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆307Updated 2 years ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆184Updated 10 months ago
- Python utility that generates "imageless" QR codes in various formats☆136Updated last year
- Generate an obfuscated DLL that will disable AMSI & ETW☆329Updated last year
- early cascade injection PoC based on Outflanks blog post☆236Updated last year
- Reaping treasures from strings in remote processes memory☆285Updated last year
- FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loadi…☆399Updated last year
- DLL proxying for lazy people☆196Updated 2 months ago
- Weaponizing DCOM for NTLM Authentication Coercions☆275Updated 7 months ago
- ☆319Updated 2 years ago
- Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8☆351Updated last year
- ☆186Updated 7 months ago
- ☆259Updated 2 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆280Updated last year
- Patch AMSI and ETW☆250Updated last year
- Rust For Windows Cheatsheet☆121Updated 2 months ago