WesleyWong420 / Build-Your-Own-LOLBinsLinks
A post-exploitation toolkit to simulate the weaponization and detection of native Windows binaries based on LOLBas framework.
☆28Updated 2 years ago
Alternatives and similar repositories for Build-Your-Own-LOLBins
Users that are interested in Build-Your-Own-LOLBins are comparing it to the libraries listed below
Sorting:
- ☆48Updated last year
- A tool for interacting with the Anti-Malware Scan Interface API for pen testing purposes.☆65Updated last year
- Finding secrets in kernel and user memory☆116Updated 2 years ago
- ☆74Updated 2 years ago
- Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers☆124Updated last year
- DEFCON30 Talk Material, References and Extra Bits☆39Updated 2 years ago
- ☆68Updated 2 years ago
- ☆76Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 2 years ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆89Updated 3 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆87Updated 2 years ago
- WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.☆55Updated 4 years ago
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆86Updated 2 months ago
- Windows internals and exploitation tricks☆106Updated 3 months ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆39Updated 3 years ago
- Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and en…☆42Updated last year
- ☆80Updated last year
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆105Updated last year
- ☆42Updated last year
- ☆82Updated 10 months ago
- ☆39Updated 2 years ago
- Slide decks and/or materials from conference presentations☆56Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆68Updated last year
- ☆121Updated last year
- A tool to exchange decryption keys for command and control (C2) beacons and implants through DNS records.☆39Updated 2 years ago
- Tool for playing with Windows Access Token manipulation.☆55Updated 2 years ago
- quASAR: ASAR manipulation made easy☆38Updated 3 years ago
- Process Monitor filter for finding privilege escalation vulnerabilities on Windows☆79Updated 4 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆42Updated 6 months ago
- Just another ntdll unhooking using Parun's Fart technique☆75Updated 2 years ago