Ghost53574 / havoc_profile_generator
Havoc C2 profile generator
☆65Updated 2 months ago
Alternatives and similar repositories for havoc_profile_generator:
Users that are interested in havoc_profile_generator are comparing it to the libraries listed below
- ☆136Updated 5 months ago
- Porting of BOF InlineExecute-Assembly to load .NET assembly in process but with patchless AMSI and ETW bypass using hardware breakpoint.☆197Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆274Updated last month
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆175Updated 2 months ago
- Just another C2 Redirector using CloudFlare.☆82Updated 8 months ago
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆149Updated last year
- a port of privkit bof for havoc☆23Updated last year
- ☆187Updated 9 months ago
- Patching AmsiOpenSession by forcing an error branching☆143Updated last year
- GregsBestFriend process injection code created from the White Knight Labs Offensive Development course☆179Updated last year
- Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods☆101Updated last year
- CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking☆220Updated last year
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆157Updated last month
- ☆218Updated 8 months ago
- Extracting NetNTLM without touching lsass.exe☆232Updated last year
- A PoC for Early Cascade process injection technique.☆90Updated last week
- 「💀」Proof of concept on BYOVD attack☆154Updated last month
- Evasive Golang Loader☆132Updated 5 months ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆84Updated 6 months ago
- AzureAD beacon object files☆105Updated last month
- ☆161Updated 2 months ago
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆193Updated 7 months ago
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆101Updated 3 weeks ago
- ☆159Updated 5 months ago
- Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST☆172Updated 4 months ago
- A C# port from Invoke-GhostTask☆112Updated last year
- Abuse leaked token handles.☆131Updated last year
- Patch AMSI and ETW☆234Updated 8 months ago
- ☆121Updated 4 months ago
- An App Domain Manager Injection DLL PoC on steroids☆164Updated last year