Wh1t3Rh1n0 / PECheck
A tool to verify and create PE Checksums for Portable Executable (PE) files.
☆51Updated last year
Alternatives and similar repositories for PECheck:
Users that are interested in PECheck are comparing it to the libraries listed below
- Python module for running BOFs☆64Updated last year
- ☆83Updated 2 years ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Living Off the Foreign Land setup scripts☆64Updated last week
- Find DLLs with RWX section☆76Updated last year
- Slide decks and/or materials from conference presentations☆55Updated 2 years ago
- ☆110Updated 3 years ago
- ☆28Updated 4 months ago
- Two in one, patch lifetime powershell console, no more etw and amsi!☆84Updated 6 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆78Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- Utilities for obfuscating shellcode☆49Updated 6 months ago
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- Sniffing files generator☆49Updated 2 months ago
- Lockless BOF☆62Updated 11 months ago
- ☆71Updated 2 years ago
- Sliver extension performing TCP redirection tasks without performing cross-process injection.☆61Updated this week
- This repo hosts a poc of how to execute F# code within an unmanaged process☆66Updated 6 months ago
- ☆40Updated this week
- Example code samples from our ScriptBlock Smuggling Blog post☆87Updated 7 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆115Updated 7 months ago
- ☆105Updated last month
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆76Updated 2 months ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆68Updated 8 months ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆88Updated 2 years ago
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 8 months ago
- ☆98Updated 9 months ago
- Evade EDR's the simple way, by not touching any of the API's they hook.☆68Updated 5 months ago