S3cur3Th1sSh1t / SharpByeBear
AppXSVC Service race condition - privilege escalation
☆27Updated 5 years ago
Alternatives and similar repositories for SharpByeBear:
Users that are interested in SharpByeBear are comparing it to the libraries listed below
- Convert Empire profiles to Apache mod_rewrite scripts☆27Updated 5 years ago
- SharpSvc is a simple code set to interact with the SC Manager API and is compatible with Cobalt Strike.☆26Updated last year
- A project to replicate the functionality of Noah Powers' ServerSetup script, but with error handling and fixed Namecheap API support.☆34Updated 3 years ago
- Get or remove RunMRU values☆55Updated 5 years ago
- Extended Process List (Search functionality)☆29Updated 4 years ago
- ☆17Updated 4 years ago
- Example of running C3 (https://github.com/FSecureLABS/C3) in a Docker container☆27Updated 3 years ago
- A C# tool to send emails through Outlook from the command line or in memory☆31Updated 4 years ago
- SharpReg is a simple code set to interact with the Remote Registry service api and is compatible with Cobalt Strike.☆29Updated 5 years ago
- Demos of Donut used in conferences, etc. Mostly for my use, but free for others to use as a reference.☆32Updated 5 years ago
- treafik fronted c2 examples☆26Updated 4 years ago
- Windows File Enumeration Intel Gathering Tool.☆17Updated last year
- Log converter from CS log to Ghostwriter CSV☆30Updated 4 years ago
- A script that can be deployed to Azure App for C2 / Proxy / Redirector☆36Updated 5 years ago
- Simple Aggressor Scripts for Cobalt Strike☆12Updated 4 years ago
- ☆37Updated 3 years ago
- C# application that allows you to quick run SSH commands against a host or list of hosts☆42Updated 4 years ago
- A Powershell module including a couple of cmdlets for EWS Enum/Exploitation.☆17Updated 5 years ago
- ☆28Updated 7 years ago
- I used this to see if an EDR is running in Safe Mode☆36Updated 4 years ago
- A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.☆19Updated 3 years ago
- IOXIDResolver from AirBus Security/PingCastle☆50Updated 4 years ago
- Core bypass Windows Defender and execute any binary converted to shellcode☆43Updated 3 years ago
- Extract all IP of a computer using DCOM without authentication (aka detect network used for administration)☆26Updated 5 years ago
- An Ansible role to install cobalt-strike☆16Updated 4 years ago
- Extracts Azure authentication tokens from PowerShell process minidumps.☆23Updated last year
- A simple injector that uses LoadLibraryA☆17Updated 4 years ago
- Microsoft Applocker evasion tool☆39Updated 5 years ago
- RID Hijacking Proof of Concept script by Kevin Joyce☆15Updated 6 years ago
- My musings with C#☆28Updated 2 years ago