Tylous / Ivy
Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environment to load, decrypt and execute shellcode.
☆21Updated 2 years ago
Alternatives and similar repositories for Ivy
Users that are interested in Ivy are comparing it to the libraries listed below
Sorting:
- Python module for running BOFs☆70Updated last year
- A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.☆14Updated 2 years ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆27Updated 3 months ago
- Simple .NET loader for loading and executing Powershell payloads☆17Updated 3 years ago
- Rewrite to fit my needs☆28Updated 9 months ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆21Updated 2 years ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆74Updated 2 years ago
- ☆48Updated last year
- Click Once + App Domain☆62Updated last year
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆85Updated 2 years ago
- A care package of useful bofs for red team engagments☆55Updated 5 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 10 months ago
- Items related to the RedELK workshop given at security conferences☆29Updated last year
- Scripts to interact with Microsoft Graph APIs☆40Updated 6 months ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆55Updated 3 years ago
- HTML smuggling is not an evil, it can be useful☆13Updated 2 years ago
- SAM Dumping in C#☆48Updated 4 months ago
- Some of the presentations, workshops, and labs I gave at public conferences.☆33Updated last week
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆70Updated last year
- Proxy function calls through the thread pool with ease☆27Updated 2 months ago
- ☆25Updated 3 years ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆33Updated last year
- A VSCode devcontainer for development of COFF files with batteries included.☆49Updated last year
- ☆59Updated last year
- C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)☆22Updated 2 years ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆39Updated 2 years ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆26Updated 2 years ago
- Bunch of BOF files☆31Updated 4 months ago
- A .NET implementation to dump SAM, SYSTEM, SECURITY registry hives from a remote host☆39Updated last year
- Windows Persistence Toolkit in C#☆36Updated 2 years ago