M0nster3 / RpcsDemoView external linksLinks
关于RPC一些绕EDR的tips
☆198Mar 3, 2023Updated 2 years ago
Alternatives and similar repositories for RpcsDemo
Users that are interested in RpcsDemo are comparing it to the libraries listed below
Sorting:
- 添加计划任务方法集合☆309Aug 6, 2023Updated 2 years ago
- Abuse Impersonate Privilege from Service to SYSTEM like other potatoes do☆400Feb 6, 2023Updated 3 years ago
- Bypass EDR Create TaskServers☆38Dec 24, 2022Updated 3 years ago
- 一种通过进程注入实现强制关闭部分杀软进程的方法(以360安全卫士和360杀毒为例)☆138Dec 26, 2023Updated 2 years ago
- dump lsass进程工具☆561Jul 20, 2023Updated 2 years ago
- Bypassing UAC with SSPI Datagram Contexts☆460Sep 24, 2023Updated 2 years ago
- Cobalt Strike 二开项目☆185Feb 11, 2023Updated 3 years ago
- Take a screenshot without injection for Cobalt Strike☆203Jun 7, 2023Updated 2 years ago
- Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThrea…☆1,289Jun 21, 2024Updated last year
- Misc TaskScheduler Plays☆238Sep 27, 2022Updated 3 years ago
- An implementation of an indirect system call☆132Aug 25, 2023Updated 2 years ago
- EDR绕过demo☆294Jan 14, 2024Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆96Mar 20, 2023Updated 2 years ago
- Pillager是一个适用于后渗透期间的信息收集工具☆1,266Sep 7, 2024Updated last year
- RPC远程主机信息匿名扫描工具☆317Sep 30, 2022Updated 3 years ago
- OrcaC2是一款基于Websocket加密通信的多功能C&C框架,使用Golang实现。☆676Dec 30, 2022Updated 3 years ago
- 根据攻防以及域信息收集经验dump快而有用的域信息☆103Aug 15, 2023Updated 2 years ago
- 寻找可利用的白文件☆556Aug 18, 2025Updated 5 months ago
- 重构Beacon☆164Aug 19, 2024Updated last year
- Fork & modify of Wireguard's Memmod☆33Aug 2, 2023Updated 2 years ago
- BOF implementation of delete self poc that delete a locked executable or a currently running file from disk by its pid, path, or the curr…☆78Jul 23, 2023Updated 2 years ago
- A little tool to play with the Seclogon service☆328Jul 10, 2022Updated 3 years ago
- ☆26Apr 24, 2025Updated 9 months ago
- Cobalt Strike BOF that Add a user to localgroup by samr☆134Nov 30, 2022Updated 3 years ago
- New generation of wmiexec.py☆1,255Jan 5, 2026Updated last month
- A BOF that runs unmanaged PEs inline☆678Oct 23, 2024Updated last year
- Execute unmanaged Windows executables in CobaltStrike Beacons☆714Mar 4, 2023Updated 2 years ago
- 远程创建任务计划工具☆190Apr 23, 2022Updated 3 years ago
- GetProcAddressByHash/remap/full dll unhooking/Tartaru's Gate/Spoofing Gate/universal/Perun's Fart/Spoofing-Gate/EGG/RecycledGate/syswhisp…☆331Sep 10, 2024Updated last year
- Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE☆205Aug 25, 2023Updated 2 years ago
- ☆32Apr 23, 2023Updated 2 years ago
- Syscall免杀☆511Jun 21, 2024Updated last year
- 替代PrintBug用于本地提权的新方式,主要利用MS-EFSR协议中的接口函数 借鉴了Potitpotam中对于EFSR协议的利用,实现了本地提权的一系列方式 Drawing on the use of the EFSR protocol in Potitpotam, …☆149Mar 13, 2022Updated 3 years ago
- Mssql利用工具☆276Aug 7, 2023Updated 2 years ago
- Burp插件,Malleable C2 Profiles生成器;可以通过Burp代理选中请求,生成Cobalt Strike的profile文件(CSprofile)☆290Jan 15, 2022Updated 4 years ago
- 一款dump hash工具配合后渗透的利用☆275Apr 21, 2023Updated 2 years ago
- ☆563Feb 22, 2024Updated last year
- Callback Function Loader Implemented in Go☆140Mar 26, 2024Updated last year
- A BOF to determine Windows Defender exclusions.☆254Jun 25, 2023Updated 2 years ago