Offensive-Panda / ShadowDumperLinks
Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive data in LSASS memory.
☆568Updated 7 months ago
Alternatives and similar repositories for ShadowDumper
Users that are interested in ShadowDumper are comparing it to the libraries listed below
Sorting:
- MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.☆535Updated last month
- Extract and execute a PE embedded within a PNG file using an LNK file.☆463Updated last year
- DeadPotato is a windows privilege escalation utility from the Potato family of exploits, leveraging the SeImpersonate right to obtain SYS…☆453Updated last year
- Windows remote execution multitool☆762Updated 3 months ago
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework☆629Updated 8 months ago
- A sophisticated, covert Windows-based credential dumper using C++ and MASM x64.☆443Updated last year
- Cobalt Strike HTTPS beaconing over Microsoft Graph API☆619Updated last year
- A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfve…☆586Updated last year
- PoC Exploit for the NTLM reflection SMB flaw.☆615Updated 6 months ago
- Collection of UAC Bypass Techniques Weaponized as BOFs☆590Updated last year
- CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File☆390Updated 9 months ago
- AdaptixFramework Extension Kit☆350Updated last week
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆529Updated 8 months ago
- Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).☆582Updated last year
- ArgFuscator.net is an open-source, stand-alone web application that helps generate obfuscated command lines for common system-native exec…☆387Updated 8 months ago
- Tool to remotely dump secrets from the Windows registry☆519Updated last month
- HookChain: A new perspective for Bypassing EDR Solutions☆581Updated last year
- Stealthily inject shellcode into an executable☆432Updated 2 months ago
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆789Updated 2 months ago
- A list of python tools to help create an OPSEC-safe Cobalt Strike profile.☆504Updated 7 months ago
- SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection s…☆443Updated last year
- ☆409Updated last year
- Amsi Bypass payload that works on Windwos 11☆377Updated 2 years ago
- Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in…☆511Updated last year
- Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)☆692Updated 8 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆452Updated last year
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆400Updated 3 months ago
- Useful C2 techniques and cheat sheets learned from engagements☆565Updated 4 months ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆531Updated last month
- AV/EDR Lab environment setup references to help in Malware development☆418Updated 10 months ago