SafeBreach-Labs / BITSInject
A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service), allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account
☆98Updated 5 years ago
Alternatives and similar repositories for BITSInject:
Users that are interested in BITSInject are comparing it to the libraries listed below
- Reflective Polymorphism☆104Updated 6 years ago
- Tool to make in memory man in the middle☆124Updated 6 years ago
- NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements☆96Updated 7 years ago
- Another Repo of Malware. Enjoy. <3☆60Updated 6 years ago
- Advanced Portable Executable File Analyzer And Disassembler 32 & 64 Bit☆99Updated 5 years ago
- Some sample code from my Zero Nights 2017 presentation.☆62Updated 7 years ago
- x86-64 Windows shellcode that recreates the Jurassic Park hacking scene (Ah, ah, ah... you didn't' say the magic word!)☆83Updated 4 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆85Updated 7 years ago
- UAC 0Day all day!☆58Updated 7 years ago
- Open Source Office Malware Generation & Polymorphic Engine for Red Teams and QA testing☆95Updated 7 years ago
- Simple DDE object detector☆56Updated 7 years ago
- Material from our CANAPE workshop☆32Updated 6 years ago
- An offensive Powershell console☆30Updated 9 years ago
- ☆51Updated 6 years ago
- Mal Tindex is an Open Source tool for indexing binaries and help attributing malware campaigns☆67Updated 7 years ago
- Proof of concept VBA code to add to Normal.dot to put restrictions on Word☆41Updated 8 years ago
- All materials from our Black Hat 2018 "Subverting Sysmon" talk☆136Updated 6 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆135Updated 7 years ago
- A tiny PoC to inject and execute code into explorer.exe with WM_SETTEXT+WM_COPYDATA+SetThreadContext☆50Updated 6 years ago
- some pocs for antivirus evasion☆130Updated last year
- ☆114Updated 7 years ago
- POLAR☆73Updated 6 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆149Updated 5 years ago
- put this here because archival reasons.☆28Updated 7 years ago
- ☆59Updated 5 years ago
- VBS Reversed TCP Meterpreter Stager☆86Updated 7 years ago
- ☆97Updated 9 years ago
- ☆34Updated 7 years ago
- Just a normal flask web app to understand win32api with code snippets and references.☆72Updated 5 years ago