Hagrid29 / BOF-DCOMPotato-PrintNotify
Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object to DCOM call of PrintNotify.
☆42Updated 2 years ago
Alternatives and similar repositories for BOF-DCOMPotato-PrintNotify:
Users that are interested in BOF-DCOMPotato-PrintNotify are comparing it to the libraries listed below
- ☆21Updated last year
- ☆40Updated last year
- Beacon Object File implementation of pwn1sher's KillDefender☆66Updated 2 years ago
- 一个普通的BOF用来BypassUAC☆18Updated 11 months ago
- command execute without 445 port☆53Updated 3 years ago
- Bypass EDR Create TaskServers☆36Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that uses LogonUserSSPI API to perform kerberos-based password spray☆44Updated 2 years ago
- ☆30Updated 2 years ago
- Execute Remote Assembly with args passing and with AMSI and ETW patching .☆32Updated 2 years ago
- Load shellcode via syscall☆47Updated 3 years ago
- Golang implement winrm client with pass the hash☆31Updated 10 months ago
- dump lsass☆37Updated 2 years ago
- ☆10Updated last year
- ☆31Updated last year
- AddDefenderExclusions Beacon Object File☆35Updated last year
- A wrapper of ldap_shell.py module which in ntlmrelayx☆62Updated 2 years ago
- Silently Install Chrome Extension For Persistence☆49Updated 8 months ago
- Fork & modify of Wireguard's Memmod☆32Updated last year
- Self Cleanup in post-ex job☆50Updated 6 months ago
- ☆26Updated last year
- Delete file regardless of whether the handle is used via SetFileInformationByHandle☆42Updated last year
- BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel☆21Updated 9 months ago
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆71Updated last year
- dump lsass tool☆39Updated 2 years ago
- ☆45Updated 8 months ago
- ASPX ShellCode Loader☆49Updated last year
- More EFS coerced authentication method with PetitPotam.py☆22Updated 2 years ago
- MSSQL CLR for pentest.☆54Updated last year
- Help red teams find opsec processes during engagements☆36Updated 3 months ago
- ☆17Updated 3 years ago