WiredPulse / Invoke-GhostLog
Removal of certain event logs within a Windows OS
☆7Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for Invoke-GhostLog
- ☆17Updated 6 years ago
- C# code to run PIC using CreateThread☆16Updated 5 years ago
- ☆24Updated 6 years ago
- ☆26Updated 6 years ago
- Retrieve the IIS Application Pool Credentials. Relies on the WebAdministration PowerShell Module.☆13Updated 6 years ago
- A simple reflective dll example☆18Updated 7 years ago
- Run Managed Assemblies with RunDll☆16Updated 6 years ago
- Files related to my presentation at SigSegV2 conference in 2019. You can find related papers on my blog☆13Updated 4 years ago
- PoC code from blog☆16Updated 4 years ago
- Python script to patch the reflective stub in a DLL☆24Updated 7 years ago
- module for certexfil☆15Updated 2 years ago
- Create COM Objects backed by Scripts, not DLLs☆9Updated 7 years ago
- A PoC to show how to add code to C# and dotNet and make it reusable for Red Team operations. Maybe one day it will be the largest collect…☆17Updated 4 years ago
- simple demo of using C# & System.Management.Automation.dll to run powershell code (b64 encoded) without powershell.exe☆13Updated 7 years ago
- RID Hijacking Proof of Concept script by Kevin Joyce☆15Updated 6 years ago
- A minimal safe version of mimikatz to only allow the export of non-exportable Windows certificates☆24Updated 6 years ago
- A PowerShell script to prevent Sysmon from writing its events☆14Updated 4 years ago
- SSDP Service Discovery☆16Updated 5 years ago
- A simple, minimal C# windows service implementation that can be used to demonstrate privilege escalation from misconfigured windows servi…☆15Updated 9 years ago
- Techniques that i have used to evade anti-virus during pen tests.☆13Updated 6 years ago
- Mimikatz HashClash☆12Updated 9 years ago
- ☆30Updated 6 years ago
- A PoC .net shell which uses a GitHub.com repository for the communication channel.☆11Updated 6 years ago
- ☆31Updated 7 years ago
- ☆11Updated 5 years ago