F4l13n5n0w / sn0wldr
This project is an AES loader for c2 shellcode
☆26Updated last year
Alternatives and similar repositories for sn0wldr
Users that are interested in sn0wldr are comparing it to the libraries listed below
Sorting:
- Repository of scripts from my blog post on bypassing the YARA rule Windows_Trojan_CobaltStrike_f0b627fc by generating alternative shellco…☆39Updated 6 months ago
- ☆97Updated last year
- ☆86Updated last year
- An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are a…☆135Updated 2 years ago
- AdaptixFramework Extension Kit☆77Updated last week
- Alternative Shellcode Execution Via Callbacks in C# with P/Invoke☆76Updated 2 years ago
- ☆225Updated last year
- Library of BOFs to interact with SQL servers☆163Updated last month
- ☆80Updated last year
- Cobalt Strike beacon object file implementation for trusted path UAC bypass. The target executable will be called without involving "cmd.…☆133Updated 3 years ago
- Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE☆205Updated last year
- Little program written in C# to bypass EDR hooks and dump the content of the lsass process☆61Updated 3 years ago
- ☆158Updated 2 years ago
- Homemade Aggressor scripts kit for Cobalt Strike☆64Updated 2 months ago
- ☆142Updated last year
- ApexLdr is a DLL Payload Loader written in C☆108Updated 9 months ago
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆153Updated last year
- CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution☆42Updated last year
- ErebusGate for Nim Bypass AV/EDR☆161Updated 2 years ago
- CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking☆226Updated last year
- A small (Edited) POC to make defender useless by removing its token privileges and lowering the token integrity☆32Updated 2 years ago
- Dumping LSASS with a duplicated handle from custom LSA plugin☆201Updated 3 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆70Updated 7 months ago
- CVE-2024-40711-exp☆41Updated 6 months ago
- Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445☆45Updated last year
- Winsocket for Cobalt Strike.☆98Updated last year
- ☆125Updated last year
- A C# port from Invoke-GhostTask☆115Updated last year
- ☆47Updated last year
- DCSync Attack from Outside using Impacket☆113Updated 3 years ago