b1tg / Ox-C2
Command & Control server and agent written in Rust
☆34Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for Ox-C2
- Inject a shellcode in a remote process using Process Hollowing.☆43Updated 3 years ago
- Host CLR and run .NET binaries using Rust☆61Updated 3 weeks ago
- 64-bit, position-independent reverse tcp shell, built in Rust for Windows.☆44Updated last month
- A work in progress BOF/COFF loader in Rust☆45Updated last year
- Rusty Hell's Gate / Halo's Gate / Tartarus' Gate / FreshyCalls / Syswhispers2 Library☆24Updated 2 years ago
- Rust port of LayeredSyscall, designed to perform indirect syscalls while generating legitimate API call stack frames by abusing Vectored …☆104Updated 3 weeks ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- Template-based generation of shellcode loaders☆67Updated 7 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆48Updated 2 weeks ago
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆75Updated last year
- abusing Process Hacker driver to terminate other processes (BYOVD)☆79Updated last year
- I have documented all of the AMSI patches that I learned till now☆68Updated last year
- Shellcode loader designed for evasion. Coded in Rust.☆107Updated last year
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- ☆118Updated last year
- Rust Implementation of SharpDllProxy for DLL Proxying Technique☆28Updated 2 years ago
- ☆96Updated last year
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆166Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆67Updated 9 months ago
- Donut generator in rust.☆23Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆78Updated last year
- ☆44Updated 2 years ago
- Repo that holds random POCs☆45Updated 10 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆58Updated 8 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated last year
- Hide memory artifacts using ROP and hardware breakpoints.☆135Updated last year