Whitecat18 / earlycascade-injection
Early cascade injection PoC based on Outflanks blog post written in Rust
☆36Updated 2 months ago
Alternatives and similar repositories for earlycascade-injection:
Users that are interested in earlycascade-injection are comparing it to the libraries listed below
- based on https://gitlab.com/ORCA000/snaploader☆42Updated last month
- BOF for C2 framework☆40Updated 2 months ago
- Beacon Object Files (BOF) for Cobalt Strike.☆27Updated 4 months ago
- ☆45Updated 2 months ago
- Sliver agent rewritten in C++☆43Updated 4 months ago
- DFSCoerce exe revisited version with custom authentication☆38Updated last year
- BYOVD collection☆21Updated 9 months ago
- convert compatible dlls to shellcode with sRDI. I don't remember where this came from, so if you recognize the code, let me know and I'll…☆12Updated 8 months ago
- in-process powershell runner for BRC4☆45Updated last year
- GPOAnalyzer is a tool designed to assist in parsing domain Group Policy Object (GPO) files located in the SYSVOL directory.☆22Updated 7 months ago
- ☆28Updated 7 months ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆41Updated 5 months ago
- Section-based payload obfuscation technique for x64☆59Updated 5 months ago
- A Dynamic MSBuild task to help with minor obfuscation of C# Binaries to evade static signatures on each compilation☆32Updated 9 months ago
- SAM Dumping in C#☆39Updated this week
- ☆19Updated 5 months ago
- Using LNK files and user input simulation to start processes under explorer.exe☆24Updated 3 months ago
- Folder Or File Delete to Get System Shell on Current Session Desktop☆19Updated this week
- Tool to aid in dumping LSASS process remotely☆35Updated 5 months ago
- A 64-bit, position-independent code reverse TCP shell for Windows — built in Rust.☆51Updated 2 weeks ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆30Updated last year
- ☆19Updated 7 months ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆45Updated 2 weeks ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆77Updated 3 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 4 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆50Updated 2 months ago
- Dynamically resolve API function addresses at runtime in a secure manner.☆46Updated 3 months ago
- Exploit for Arbitrary File Move vulnerability in ZoneAlarm AV☆26Updated 2 years ago