GrayKernel / GrayStorm
In memory attack platform for C# Applications
☆51Updated 5 years ago
Alternatives and similar repositories for GrayStorm:
Users that are interested in GrayStorm are comparing it to the libraries listed below
- C++ DLL Bootstrapper for spinning up the CLR for C# Payloads☆42Updated 5 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆148Updated 5 years ago
- All TMF files that I extracted from Microsoft PDBs.☆12Updated 5 years ago
- Inject .Net payloads into other .Net assemblies on disk☆61Updated 5 years ago
- A tiny PoC to inject and execute code into explorer.exe with WM_SETTEXT+WM_COPYDATA+SetThreadContext☆50Updated 6 years ago
- Shim database persistence (Fin7 TTP)☆36Updated 4 years ago
- ☆33Updated 5 years ago
- A Generic Windows Memory Scraping Tool☆70Updated 7 years ago
- A set of demos and a PowerShell module to interact with DotNetInterop.☆67Updated 6 years ago
- A tool to exploit .NET DCOM for EoP and RCE. Is fixed in latest versions of the .NET.☆87Updated 10 years ago
- Provides the ability to patch/hook functions imported by a dll or executable☆34Updated 14 years ago
- ☆62Updated 8 years ago
- ☆45Updated 6 years ago
- Tool for injecting a "TCP Relay" managed assembly into an unmanaged process☆64Updated 5 years ago
- A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service), allowing arbitrary program execution as th…☆98Updated 5 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆133Updated 7 years ago
- Reflective Polymorphism☆104Updated 6 years ago
- A collection of tools to enumerate and analyse Windows DACLs☆106Updated 9 years ago
- DLL Injection Library & Tools☆71Updated 8 years ago
- ☆41Updated 5 years ago
- Privilege Escilation training project, with an emphasis on the distinction between vulnerability research & it's exposure and exploitatio…☆35Updated 8 years ago
- C# code to run shellcode in a sneaky way☆90Updated 4 years ago
- Run Managed Assemblies with RunDll☆16Updated 6 years ago
- CmdDesktopSwitch is a small utility that lists all windows desktops and provides the option to switch between them. This can be used to i…☆34Updated 8 years ago
- PoC dlls for Task Scheduler COM Hijacking☆90Updated 8 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 3 years ago
- fragments of dirty, and quick code. possible error checking or none.☆25Updated 7 years ago
- An example pattern in C# for using WMI to monitor process creation and termination events.☆51Updated 6 years ago
- Windows Process Injection Toolkit - plain and simple :)☆26Updated 6 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆73Updated 4 years ago