WesleyWong420 / Build-Your-Own-LOLBinsLinks
A post-exploitation toolkit to simulate the weaponization and detection of native Windows binaries based on LOLBas framework.
☆29Updated 2 years ago
Alternatives and similar repositories for Build-Your-Own-LOLBins
Users that are interested in Build-Your-Own-LOLBins are comparing it to the libraries listed below
Sorting:
- ☆48Updated last year
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆62Updated last year
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆41Updated 9 months ago
- Finding secrets in kernel and user memory☆116Updated last year
- ☆67Updated 2 years ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆83Updated last year
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆38Updated 3 years ago
- a tiny program to consume from ETW providers for research☆49Updated 6 months ago
- ☆74Updated 2 years ago
- Windows internals and exploitation tricks☆102Updated 3 weeks ago
- Freyja is a Golang, Purple Team agent that compiles into Windows, Linux and macOS x64 executables.☆59Updated 8 months ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 2 years ago
- ☆76Updated 11 months ago
- ☆78Updated last year
- ☆38Updated 2 years ago
- Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers☆122Updated 10 months ago
- ☆42Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆85Updated 2 years ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- Slide decks and/or materials from conference presentations☆56Updated 2 years ago
- DEFCON30 Talk Material, References and Extra Bits☆39Updated 2 years ago
- ☆81Updated 7 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- Windows API header file parsing tool to generate source code for Windows API hashing☆5Updated 2 years ago
- ☆45Updated last year
- ☆23Updated last year
- quASAR: ASAR manipulation made easy☆38Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆68Updated last year
- ☆69Updated last year
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆62Updated last year