Blue Hammer by Nightmare-Eclipse Vulnerability Documentation & Reimplementation.
☆217May 8, 2026Updated 3 months ago
Alternatives and similar repositories for SNEK_Blue-War-Hammer
Users that are interested in SNEK_Blue-War-Hammer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Reattempt of BlueHammer disclosed in April 2026☆68May 11, 2026Updated 2 months ago
- RoguePlanet Windows Defender Vulnerability☆1,579Jun 9, 2026Updated 2 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- POC for CVE-2023-29360☆11Aug 31, 2024Updated last year
- C# implementation of the process injection techniques dubbed "PoolParty"☆17Nov 7, 2025Updated 9 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆31Apr 2, 2026Updated 4 months ago
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 4 months ago
- GreatXML bitlocker bypass vulnerability☆614Jun 11, 2026Updated 2 months ago
- Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest clea…☆45Mar 27, 2026Updated 4 months ago
- Adaptix C2 extender to support Cobalt Strike Malleable C2 profiles☆51Jun 28, 2026Updated last month
- Active Directory information dumper via ADWS for evasion purposes.☆316Jul 9, 2026Updated last month
- Proof-of-Concept software for creating inbound AD forest trusts.☆21Jun 25, 2025Updated last year
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆238Apr 11, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆147Mar 29, 2025Updated last year
- Kernel Information Disclosure☆35Jan 13, 2026Updated 6 months ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆167Apr 15, 2026Updated 3 months ago
- template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.☆107Jan 10, 2026Updated 7 months ago
- Solemn is a lightweight command-line tool for Windows that automates adding drivers to the HVCI (HvciDisallowedImages) custom blocklist☆25May 2, 2026Updated 3 months ago
- Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.☆396Jun 20, 2026Updated last month
- The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver☆50Mar 13, 2026Updated 4 months ago
- modified mssqlclient from impacket to extract policies from the SCCM database☆48Feb 24, 2026Updated 5 months ago
- Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime☆98Mar 29, 2026Updated 4 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, wit…☆297Feb 21, 2026Updated 5 months ago
- Obex – Blocking unwanted DLLs in user mode☆281Sep 18, 2025Updated 10 months ago
- AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64☆551Mar 7, 2026Updated 5 months ago
- A credential extraction BOF for Veeam Backup and Replication and Veeam One☆79Jul 1, 2026Updated last month
- ☆194Oct 21, 2025Updated 9 months ago
- Run PowerShell command without invoking powershell.exe☆27Apr 9, 2026Updated 4 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated 2 weeks ago
- Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows …☆268Sep 23, 2025Updated 10 months ago
- Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler☆19Jul 2, 2026Updated last month
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- BOF to manage Active Directory Integrated DNS (ADIDNS)☆28Jul 28, 2025Updated last year
- Windows AppLocker Driver (appid.sys) LPE☆80Jul 29, 2024Updated 2 years ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- Kernel Process Termination Tool ( CVE-2026-0828 exploit)☆38Apr 2, 2026Updated 4 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆415Updated this week
- Validates priv escalation of AD trusts☆47Apr 1, 2025Updated last year
- PPLwindow PPL Bypass via GetProcessHandleFromHwnd☆54Dec 29, 2025Updated 7 months ago