brett-fitz / pyMalleableProfileParserLinks
Parses Cobalt Strike malleable C2 profiles.
☆58Updated last week
Alternatives and similar repositories for pyMalleableProfileParser
Users that are interested in pyMalleableProfileParser are comparing it to the libraries listed below
Sorting:
- Modified versions of the Cobalt Strike Process Injection Kit☆95Updated last year
- Active Directory certificate abuse☆39Updated 2 years ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- Cobalt Strike BOF for quser.exe implementation using Windows API☆86Updated 2 years ago
- Run Cobalt Strike BOFs in Brute Ratel C4!☆67Updated 2 months ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆84Updated 2 years ago
- ☆127Updated last year
- ☆26Updated 7 months ago
- Windows Persistence Toolkit in C#☆36Updated 2 years ago
- Alternative Shellcode Execution Via Callbacks in C# with P/Invoke☆78Updated 2 years ago
- Aggressor script add-in for CobaltStrike to track file uploads☆36Updated 2 years ago
- ☆97Updated 9 months ago
- DLL Exports Extraction BOF with optional NTFS transactions.☆82Updated 3 years ago
- ☆71Updated last year
- A care package of useful bofs for red team engagments☆55Updated 6 months ago
- C# implementation of Get-AADIntSyncCredentials from AADInternals, which extracts Azure AD Connect credentials to AD and Azure AD from AAD…☆40Updated 2 years ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆57Updated 2 years ago
- ☆81Updated last year
- Beacon Object Files (not Buffer Overflows)☆56Updated 2 years ago
- ☆142Updated 2 years ago
- CVE-2024-40711-exp☆42Updated 8 months ago
- Beacon Object File allowing creation of Beacons in different sessions.☆80Updated 3 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆27Updated 4 years ago
- Beacon Object File to locate and suspend the threads hosting the Event Log service☆26Updated 3 years ago
- Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly☆117Updated 8 months ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆72Updated 8 months ago
- Lateral Movement via the .NET Profiler☆82Updated 7 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆93Updated last month
- A third-party Gopher Assassin for the Havoc Framework.☆44Updated last year
- Tool to bypass LSA Protection (aka Protected Process Light)☆54Updated 5 months ago