EspressoCake / Process_Protection_Level_BOF
☆51Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for Process_Protection_Level_BOF
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆51Updated 4 years ago
- A BOF to interact with COM objects associated with the Windows software firewall.☆100Updated 3 years ago
- ☆35Updated 2 years ago
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- ☆24Updated 3 years ago
- The repository that complements the From zero to hero: creating a reflective loader in C# workshop☆37Updated 3 years ago
- Collection of Beacon Object Files (BOFs) for shells and lols☆111Updated 3 years ago
- aggressor and pycobalt scripts.☆18Updated 4 years ago
- WhoAmI by asking the LDAP service on a domain controller.☆58Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆65Updated 4 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- A care package of useful bofs for red team engagments☆48Updated 2 years ago
- Python module for running BOFs☆64Updated last year
- C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)☆21Updated last year
- Generate droppers with encrypted payloads automatically.☆54Updated 3 years ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- ☆90Updated 3 years ago
- Grab unsaved Notepad contents with a Beacon Object File☆48Updated 2 years ago
- ☆68Updated last year
- .NET project for installing Persistence☆64Updated 2 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆25Updated 3 years ago
- ☆54Updated 3 years ago
- Click Once + App Domain☆62Updated 11 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- Weaponizing CLRvoyance for Post-Ex .NET Execution☆35Updated 3 years ago
- MiniDumpWriteDump behavior modification hook☆49Updated 3 years ago
- A simplified version of DotNetToJScript to create a JScript file which loads a .NET v2 assembly from memory.☆47Updated 3 years ago
- Scripts for public use that we've randomly written, or have updated from other people's work.☆38Updated 4 months ago
- ☆91Updated 2 years ago