Offensive-Panda / WPM-MAJIC-ENTRY-POINT-INJECTIONLinks
This exploit is utilising AddressOfEntryPoint of process which is RX and using WriteProcessMemory internal magic to change the permission and write the shellcode.
☆18Updated last year
Alternatives and similar repositories for WPM-MAJIC-ENTRY-POINT-INJECTION
Users that are interested in WPM-MAJIC-ENTRY-POINT-INJECTION are comparing it to the libraries listed below
Sorting:
- Extension functionality for the NightHawk operator client☆26Updated 2 years ago
- Repository to gather the BOF files I will be developing☆11Updated last year
- Creation and removal of Defender path exclusions and exceptions in C#.☆33Updated 2 years ago
- An interactive TUI tool to create Brute Ratel C4 profiles based on BURP browsing data.☆31Updated 7 months ago
- Aggressor script to automatically download and load an arsenal of open source and private Cobalt Strike tooling.☆45Updated last year
- Windows Access token manipulation tool made in C#☆24Updated 4 months ago
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆20Updated last year
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated 11 months ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆34Updated 2 years ago
- A simple rpc2socks alternative in pure Go.☆31Updated last year
- Example of using Sleep to create better named pipes.☆41Updated 2 years ago
- Cobalt Strike notifications via NTFY.☆15Updated last year
- havoc2nginx is a simple python script that converts Havoc Framework's yaotl malleable c2 profile to Nginx configuration file format. Most…☆12Updated 2 years ago
- ☆29Updated last year
- An improvement and a different approach to Mockingjay Self-Injection.☆35Updated last year
- ☆47Updated 2 years ago
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆25Updated 2 years ago
- Golang PoC that sandboxes Defender (or other PPL) by setting its token integrity to Untrusted.☆12Updated 7 months ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆46Updated last year
- Bunch of BOF files☆37Updated 6 months ago
- Golang Implementation of Hell's gate☆21Updated 2 years ago
- Just another Process Injection using Process Hollowing technique.☆19Updated 2 years ago
- ☆18Updated last year
- ☆38Updated 10 months ago
- Parser and reconciliation tooling for large Active Directory environments.☆33Updated 11 months ago
- These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be…☆22Updated 2 years ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆28Updated last year
- Proxy function calls through the thread pool with ease☆31Updated 10 months ago
- A simple BOF that disables some logging with NtSetInformationProcess☆13Updated 2 years ago
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆13Updated 6 months ago