b1-team / phantom
A memory-based evasion technique which makes shellcode invisible from process start to end.
☆16Updated last year
Alternatives and similar repositories for phantom:
Users that are interested in phantom are comparing it to the libraries listed below
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆43Updated 2 years ago
- A Simple PoC☆20Updated 10 months ago
- BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel☆21Updated 9 months ago
- Cobalt Strike Beacon Object File (BOF) that uses LogonUserSSPI API to perform kerberos-based password spray☆44Updated 2 years ago
- This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built i…☆33Updated 3 years ago
- ELF Beacon Object File (BOF) Template☆48Updated 4 months ago
- This contains a number of examples demonstrating how to use callback functions in supported aggressor script functions☆31Updated last week
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆32Updated 2 years ago
- Fork & modify of Wireguard's Memmod☆32Updated last year
- ☆15Updated 2 years ago
- Beacon Debugger☆40Updated 4 months ago
- ☆26Updated last year
- BOF/COFF obj file to PIC(shellcode). by golang☆37Updated 2 years ago
- ☆39Updated last year
- Beacon Object File to delete token privileges and lower the integrity level to untrusted for a specified process☆42Updated 2 years ago
- Reflective DLL injection Execution☆19Updated 2 years ago
- Golang implementation of @CCob's C# ThreadlessInject☆32Updated 10 months ago
- ☆19Updated 2 years ago
- x64 version☆30Updated 3 years ago
- Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF☆41Updated 2 years ago
- impersonate trustedinstaller by fiddling with tokens☆17Updated 3 years ago
- Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object t…☆42Updated 2 years ago
- Using LNK files and user input simulation to start processes under explorer.exe☆24Updated 6 months ago
- (Hellsgate|Halosgate|Tartarosgate)+Spoofing-Gate. Ensures that all systemcalls go through ntdll.dll☆43Updated 3 years ago
- 看起来叫BabyBypass,实际啥都会记一些☆15Updated last year
- A work in progress of constructing a minimal http(s) beacon for Cobalt Strike.☆19Updated 2 years ago
- Cs-Sleep-Mask-Fiber☆17Updated 6 months ago
- Use the Netlogon Remote Protocol (MS-NRPC) to dump the target hash.☆46Updated last month
- ☆40Updated last year
- A simple BOF (Beacon Object File) to search files in the system☆12Updated last year