Leo4j / PPLKiller
Tool to bypass LSA Protection (aka Protected Process Light)
☆29Updated this week
Alternatives and similar repositories for PPLKiller:
Users that are interested in PPLKiller are comparing it to the libraries listed below
- SAM Dumping in C#☆36Updated 6 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆24Updated 2 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆90Updated 10 months ago
- DFSCoerce exe revisited version with custom authentication☆38Updated 11 months ago
- ☆62Updated 10 months ago
- GPOAnalyzer is a tool designed to assist in parsing domain Group Policy Object (GPO) files located in the SYSVOL directory.☆21Updated 6 months ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated 11 months ago
- A Dynamic MSBuild task to help with minor obfuscation of C# Binaries to evade static signatures on each compilation☆31Updated 8 months ago
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆37Updated 11 months ago
- Beacon Object Files (not Buffer Overflows)☆52Updated last year
- Copy metadata and digital signatures information from one Windows executable to another using Wine on a non-Windows platform☆16Updated 8 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆74Updated 2 months ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- based on https://gitlab.com/ORCA000/snaploader☆36Updated 2 weeks ago
- Office 365 and Exchange Enumeration Version 2☆18Updated 10 months ago
- ☆90Updated 3 months ago
- Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute☆19Updated 6 months ago
- ☆28Updated 6 months ago
- ☆24Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆80Updated last year
- Tool to aid in dumping LSASS process remotely☆27Updated 4 months ago
- ProcExp Driver (Ab)use☆20Updated last year
- A VSCode plugin to assist with BOF development.☆30Updated 4 months ago
- ☆80Updated 6 months ago
- CVE-2024-40711-exp☆35Updated 2 months ago
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆24Updated last year
- ☆60Updated 4 months ago
- Beacon Object Files (BOF) for Cobalt Strike.☆28Updated 3 months ago