ProcessusT / CobaltStrikeBypassDefenderLinks
A launcher to load a DLL with xored cobalt strike shellcode executed in memory through process hollowing technique
☆27Updated 2 years ago
Alternatives and similar repositories for CobaltStrikeBypassDefender
Users that are interested in CobaltStrikeBypassDefender are comparing it to the libraries listed below
Sorting:
- Just another Process Injection using Process Hollowing technique.☆17Updated last year
- This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for loc…☆51Updated 2 years ago
- ☆19Updated 2 years ago
- This is a CS project that will encrypt shell code from msfvenom using AES☆22Updated 3 years ago
- The Web UI for Antnium☆27Updated 3 years ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆85Updated 2 years ago
- A proof-of-concept created for academic/learning purposes, demonstrating both local and remote use of VSTO "Add-In's" maliciously☆31Updated 2 years ago
- Extracting Clear Text Passwords from mstsc.exe using API Hooking.☆16Updated 5 years ago
- API Hammering with C++20☆49Updated 2 years ago
- freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package☆33Updated 2 years ago
- Bypass UAC on Windows 10/11 x64 using ms-settings DelegateExecute registry key.☆77Updated 2 years ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 10 months ago
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆41Updated last year
- Slides and POC demo for my talk at Divizion Zero on EDR evasion titled "Evasion Adventures"☆28Updated 2 years ago
- XOR-based shellcode encoder☆31Updated 2 years ago
- Artemis - C++ Hell's Gate Syscall Implementation☆33Updated last year
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 7 months ago
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated last year
- Various methods of executing shellcode☆71Updated 2 years ago
- ☆40Updated 2 years ago
- This is my own implementation of the Perun's Fart technique by Sektor7☆71Updated 3 years ago
- Just another ntdll unhooking using Parun's Fart technique☆75Updated 2 years ago
- Stealthy Loader-cum-dropper/stage-1/stager targeting Windows10☆37Updated 2 years ago
- A method to execute shellcode using RegisterWaitForInputIdle API.☆54Updated 2 years ago
- PDF Icon File Type Spoofer☆16Updated last year
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 3 years ago
- Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement☆65Updated 3 years ago
- ☆36Updated 2 years ago
- C++ Code to perform a MiniDump of lsass.exe☆34Updated last year
- This is a simple example of DLL hijacking enabling proxy execution.☆66Updated 2 years ago