VirtualAlllocEx / DSC_SVC_REMOTE
This code example allows you to create a malware.exe sample that can be run in the context of a system service, and could be used for local privilege escalation in the context of an unquoted service path, etc. The payload itself can be remotely hosted, downloaded via the wininet library and then executed via direct system calls.
☆51Updated last year
Alternatives and similar repositories for DSC_SVC_REMOTE:
Users that are interested in DSC_SVC_REMOTE are comparing it to the libraries listed below
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆83Updated 2 years ago
- in-process powershell runner for BRC4☆44Updated last year
- ☆47Updated 2 years ago
- PowerShell script to terminate protected processes such as anti-malware and EDRs.☆26Updated last year
- lsassdump via RtlCreateProcessReflection and NanoDump☆76Updated 4 months ago
- C# havoc implant☆98Updated 2 years ago
- Just another ntdll unhooking using Parun's Fart technique☆73Updated 2 years ago
- ☆58Updated last year
- C++ Staged Shellcode Loader with Evasion capabilities.☆80Updated 4 months ago
- These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be…☆19Updated last year
- Lateral Movement via the .NET Profiler☆79Updated 3 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 7 months ago
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆62Updated last month
- Duplicate not owned Token from Running Process☆72Updated last year
- ☆28Updated 8 months ago
- Rewrite to fit my needs☆27Updated 7 months ago
- ☆47Updated last year
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆68Updated 9 months ago
- A care package of useful bofs for red team engagments☆54Updated 2 months ago
- malleable profile generator GUI for Havoc☆56Updated last year
- Modified versions of the Cobalt Strike Process Injection Kit☆92Updated last year
- Reasonably undetected shellcode stager and executer.☆35Updated 5 months ago
- Run Cobalt Strike BOFs in Brute Ratel C4!☆61Updated last month
- DFSCoerce exe revisited version with custom authentication☆38Updated last year
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 5 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated 11 months ago
- ☆52Updated 3 months ago
- Small project to facilitate creation of .lnk payloads☆63Updated 2 years ago
- A repository with my code snippets for research/education purposes.☆50Updated last year