MaangoTaachyon / SelfDeletion-UpdatedView external linksLinks
Updated version of a long known self deletion technique to work with 24H2.
☆61Jun 9, 2025Updated 8 months ago
Alternatives and similar repositories for SelfDeletion-Updated
Users that are interested in SelfDeletion-Updated are comparing it to the libraries listed below
Sorting:
- Cobalt Strike UDRL for memory scanner evasion.☆52Dec 4, 2023Updated 2 years ago
- malware written for educational purposes☆71Dec 31, 2025Updated last month
- Powershell and python utilties for Entra Connect☆27Jun 5, 2025Updated 8 months ago
- ☆46Jun 21, 2023Updated 2 years ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆63Mar 19, 2024Updated last year
- An interactive TUI tool to create Brute Ratel C4 profiles based on BURP browsing data.☆31May 23, 2025Updated 8 months ago
- ☆106Aug 21, 2024Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆280Sep 18, 2024Updated last year
- remote process injections using pool party techniques☆70Jun 29, 2025Updated 7 months ago
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆75Oct 27, 2025Updated 3 months ago
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆18Jun 20, 2025Updated 7 months ago
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆92Jan 8, 2025Updated last year
- ☆53Sep 23, 2025Updated 4 months ago
- Windows Administrator level Implant.☆50Sep 28, 2024Updated last year
- CyberShield 2025 Intro to EDR Evasion Class☆17Jun 3, 2025Updated 8 months ago
- Ludus role for deploying a Cobalt Strike Teamserver onto Linux servers☆18Mar 19, 2025Updated 10 months ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Apr 14, 2025Updated 10 months ago
- tool for enumeration & bulk download of sensitive files found in SharePoint environments☆79Apr 2, 2025Updated 10 months ago
- Silently Install Chrome Extension For Persistence☆97Jul 20, 2024Updated last year
- ☆60Oct 24, 2025Updated 3 months ago
- miscellaneous codes☆36Sep 24, 2023Updated 2 years ago
- Mythic C2 Agent written in x64 PIC C☆84Jan 29, 2025Updated last year
- ClickForClickOnce - Generate configurable clickonce payloads☆88Oct 10, 2025Updated 4 months ago
- Threadless shellcode injection tool☆68Aug 5, 2024Updated last year
- C2 Agent fully PIC for Mythic with advanced evasion capabilities, dotnet/powershell/shellcode/bof memory executions, lateral moviments, p…☆196Dec 30, 2025Updated last month
- Python3 implementation of ADRecon with support for NTLM and Kerberos authentication. Generates individual CSV files and a single XSLX rep…☆24Updated this week
- A BOF that's a BOF Loader and more☆196Jan 17, 2026Updated 3 weeks ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75May 1, 2024Updated last year
- Implementing an early exception handler for hooking and threadless process injection without relying on VEH or SEH☆136Aug 31, 2025Updated 5 months ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆81Jan 26, 2026Updated 2 weeks ago
- ☆47Dec 5, 2025Updated 2 months ago
- A C# port from Invoke-GhostTask☆119Jan 5, 2024Updated 2 years ago
- One WSL BOF to rule them all☆138Jan 14, 2026Updated last month
- Huffman Coding in Shellcode Obfuscation & Dynamic Indirect Syscalls Loader.☆282Apr 6, 2025Updated 10 months ago
- Work, timer, and wait callback example using solely Native Windows APIs.☆88Feb 11, 2024Updated 2 years ago
- Brute Ratel External C2 (Microsoft Teams)☆38Dec 11, 2024Updated last year
- C# alternative to the linux "cat" command... Prints file contents to console. For use with Cobalt Strike's Execute-Assembly☆15Jul 15, 2021Updated 4 years ago
- An App Domain Manager Injection DLL PoC on steroids☆210Dec 14, 2023Updated 2 years ago
- 64-bit, position-independent implant template for Windows in Rust.☆172Nov 28, 2025Updated 2 months ago