Kudaes / MFToolLinks
Direct access to NTFS volumes
☆293Updated 4 months ago
Alternatives and similar repositories for MFTool
Users that are interested in MFTool are comparing it to the libraries listed below
Sorting:
- Obex – Blocking unwanted DLLs in user mode☆278Updated 3 months ago
- A Mythic Agent written in PIC C.☆207Updated 11 months ago
- AppLocker-Based EDR Neutralization☆261Updated 3 weeks ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆164Updated 5 months ago
- ☆161Updated 7 months ago
- early cascade injection PoC based on Outflanks blog post☆236Updated last year
- PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads☆238Updated 2 months ago
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆211Updated last year
- A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and …☆187Updated 8 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆137Updated 4 months ago
- Windows Session Hijacking via COM☆329Updated last month
- A PoC for Early Cascade process injection technique.☆206Updated 11 months ago
- Stage 0☆169Updated last year
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆207Updated last year
- Flexible LDAP proxy that can be used to inspect & transform all LDAP packets generated by other tools on the fly.☆182Updated 3 weeks ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆194Updated last year
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆202Updated 9 months ago
- RunPE implementation with multiple evasive techniques (2)☆265Updated 3 months ago
- ForsHops☆152Updated 9 months ago
- Activation Context Hijack☆169Updated 5 months ago
- Shellcode injection using the Windows Debugging API☆153Updated last week
- Ghosting-AMSI☆220Updated 8 months ago
- A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.☆167Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆250Updated this week
- Gain insights into MS-RPC implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By f…☆325Updated 2 months ago
- Payload encoding utility to effectively lower payload entropy.☆121Updated 9 months ago
- ☆242Updated last year
- Python utility that generates "imageless" QR codes in various formats☆132Updated last year
- Evade EDR's the simple way, by not touching any of the API's they hook.☆169Updated 11 months ago
- Group Policy Objects manipulation and exploitation framework☆284Updated last month