Evasive loader for .NET Framework assemblies
☆52May 14, 2026Updated 3 months ago
Alternatives and similar repositories for PositiveIntent
Users that are interested in PositiveIntent are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆68Jul 12, 2026Updated 2 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆37May 12, 2026Updated 4 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp…☆75Feb 17, 2026Updated 6 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated 3 months ago
- A stealthier approach to WMI-based command execution using Impacket without touching the disk.☆87Mar 15, 2026Updated 5 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ASPX Web Shell with COFF Loader☆137Mar 10, 2026Updated 6 months ago
- Chisel new generation, written in rust. SSH under WSS with some customization.☆136Jan 24, 2026Updated 7 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆80Jul 1, 2026Updated 2 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 5 months ago
- .NET CLR-Stomping☆148May 20, 2026Updated 3 months ago
- COM Windows Persistence Technique☆90Apr 27, 2026Updated 4 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated last month
- EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies☆47Jun 8, 2026Updated 3 months ago
- dcsync bof☆54Feb 13, 2026Updated 7 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆168Apr 15, 2026Updated 4 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆135Jul 23, 2026Updated last month
- abusing windows toast notifications for fun and user manipulation☆105Jul 11, 2026Updated 2 months ago
- Tailscale/Headscale C2 profile and agent for Mythic☆34Mar 14, 2026Updated 5 months ago
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 4 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆255Mar 15, 2026Updated 5 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆47Aug 5, 2025Updated last year
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 5 months ago
- A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.☆135Mar 30, 2026Updated 5 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- One WSL BOF to rule them all☆190Jan 14, 2026Updated 7 months ago
- Beacon Object File to Enable Chrome DevTools Protocol (CDP)☆128Aug 22, 2026Updated 3 weeks ago
- UDC2 implementation that provides an ICMP C2 channel☆131Nov 24, 2025Updated 9 months ago
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆27Apr 20, 2026Updated 4 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 4 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 8 months ago
- C# to read WIM files over the network without transferring the whole file☆40Jan 22, 2026Updated 7 months ago
- A C# tool for extracting information from SCCM PXE boot media.☆57May 21, 2026Updated 3 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust,…☆156Aug 31, 2026Updated last week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Folder Or File Delete to Get System Shell on Current Session Desktop☆49Jan 14, 2025Updated last year
- The Azure Execution Tool☆159Feb 6, 2026Updated 7 months ago
- Activation Context Hijacking Evasion Tool☆305Jun 17, 2026Updated 2 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆292Jun 22, 2026Updated 2 months ago
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆255Aug 4, 2026Updated last month
- NT AFD.sys file downloader (Windows 10/11 x64)☆39Mar 18, 2026Updated 5 months ago
- ☆89Sep 3, 2026Updated last week