A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection. This PoC showcases bypassing code integrity checks and loading malicious payloads in highly protected processes such as LSASS. Based on research from James Forshaw.
☆335Mar 6, 2025Updated last year
Alternatives and similar repositories for ComDotNetExploit
Users that are interested in ComDotNetExploit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆396Dec 13, 2024Updated last year
- ForsHops☆156Mar 25, 2025Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆285Sep 18, 2024Updated 2 years ago
- Activation Context Hijack☆181May 4, 2026Updated 4 months ago
- A set of programs for analyzing common vulnerabilities in COM☆265Sep 8, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Reaping treasures from strings in remote processes memory☆287Feb 8, 2025Updated last year
- Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.☆242May 4, 2026Updated 4 months ago
- Sleep obfuscation☆275Dec 13, 2024Updated last year
- Bypass Credential Guard by patching WDigest.dll using only NTAPI functions☆269Apr 8, 2025Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆361Nov 19, 2024Updated last year
- "Service-less" driver loading☆191Nov 28, 2024Updated last year
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆219Feb 6, 2025Updated last year
- ☆199Mar 28, 2025Updated last year
- Cobaltstrike Reflective Loader with Synthetic Stackframe☆193Jan 17, 2026Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆126Sep 1, 2024Updated 2 years ago
- Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll☆154Apr 18, 2025Updated last year
- ☆135Feb 11, 2025Updated last year
- Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking☆150Jul 2, 2025Updated last year
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆463Jun 27, 2025Updated last year
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆73May 1, 2024Updated 2 years ago
- .NET assembly loader with patchless AMSI and ETW bypass☆388Apr 19, 2023Updated 3 years ago
- Local SYSTEM auth trigger for relaying☆173Jul 22, 2025Updated last year
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆140Jan 17, 2026Updated 8 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆439Sep 29, 2025Updated 11 months ago
- An example reference design for a proposed BOF PE☆246Jan 23, 2026Updated 7 months ago
- Tool for viewing NTDS.dit☆202Mar 14, 2025Updated last year
- Lateral movement with DCOM DLL hijacking☆183Jul 4, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆410Jan 11, 2026Updated 8 months ago
- NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-bui…☆241Feb 12, 2025Updated last year
- This is the loader that supports running a program with Protected Process Light (PPL) protection functionality.☆309May 23, 2026Updated 3 months ago
- BOF with Synthetic Stackframe☆263Oct 30, 2025Updated 10 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Weaponizing DCOM for NTLM Authentication Coercions☆274Jul 1, 2025Updated last year
- COM ViewLogger — new malware keylogging technique☆409Jan 6, 2025Updated last year
- A BOF that runs unmanaged PEs inline☆702Oct 23, 2024Updated last year
- early cascade injection PoC based on Outflanks blog post☆240Nov 7, 2024Updated last year
- A beacon object file implementation of PoolParty Process Injection Technique.☆458Dec 21, 2023Updated 2 years ago
- Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames☆156Nov 23, 2025Updated 9 months ago
- Fileless atexec, no more need for port 445☆413Mar 28, 2024Updated 2 years ago