Blue Hammer by Nightmare-Eclipse Vulnerability Documentation & Reimplementation.
☆219May 8, 2026Updated 4 months ago
Alternatives and similar repositories for SNEK_Blue-War-Hammer
Users that are interested in SNEK_Blue-War-Hammer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Analysis and detection engineering for the BlueHammer Windows Defender local privilege escalation vulnerability. This repo includes bug f…☆97Apr 8, 2026Updated 5 months ago
- Reattempt of BlueHammer disclosed in April 2026☆68May 11, 2026Updated 4 months ago
- RoguePlanet Windows Defender Vulnerability☆1,668Jun 9, 2026Updated 3 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆42May 27, 2026Updated 3 months ago
- POC for CVE-2023-29360☆11Aug 31, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- C# implementation of the process injection techniques dubbed "PoolParty"☆17Nov 7, 2025Updated 10 months ago
- ☆31Apr 2, 2026Updated 5 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆39Apr 6, 2026Updated 5 months ago
- Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest clea…☆45Mar 27, 2026Updated 5 months ago
- GreatXML bitlocker bypass vulnerability☆665Jun 11, 2026Updated 3 months ago
- Adaptix C2 extender to support Cobalt Strike Malleable C2 profiles☆50Jun 28, 2026Updated 2 months ago
- Active Directory information dumper via ADWS for evasion purposes.☆320Jul 9, 2026Updated 2 months ago
- Proof-of-Concept software for creating inbound AD forest trusts.☆20Jun 25, 2025Updated last year
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆105Apr 4, 2026Updated 5 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆242Apr 11, 2026Updated 5 months ago
- ☆146Mar 29, 2025Updated last year
- Kernel Information Disclosure☆35Jan 13, 2026Updated 8 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 5 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆106Jan 10, 2026Updated 8 months ago
- Solemn is a lightweight command-line tool for Windows that automates adding drivers to the HVCI (HvciDisallowedImages) custom blocklist☆25May 2, 2026Updated 4 months ago
- Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.☆400Updated this week
- The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver☆48Mar 13, 2026Updated 6 months ago
- modified mssqlclient from impacket to extract policies from the SCCM database☆49Feb 24, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, wit…☆296Feb 21, 2026Updated 6 months ago
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆102Mar 29, 2026Updated 5 months ago
- Obex – Blocking unwanted DLLs in user mode☆280Sep 18, 2025Updated last year
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆560Mar 7, 2026Updated 6 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆80Updated this week
- ☆193Oct 21, 2025Updated 10 months ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 5 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated last month
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆267Sep 23, 2025Updated 11 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler☆20Jul 2, 2026Updated 2 months ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 5 months ago
- BOF to manage Active Directory Integrated DNS (ADIDNS)☆27Jul 28, 2025Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆82Jul 29, 2024Updated 2 years ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆420Sep 3, 2026Updated 2 weeks ago
- Kernel Process Termination Tool ( CVE-2026-0828 exploit)☆36Apr 2, 2026Updated 5 months ago
- ☆103Updated this week