brosck / L1LKiller
「⚠️」Performing a BYOVD on the truesight.sys driver
☆34Updated 5 months ago
Alternatives and similar repositories for L1LKiller:
Users that are interested in L1LKiller are comparing it to the libraries listed below
- ☆55Updated 6 months ago
- POC for CVE-2024-3183 (FreeIPA Rosting)☆20Updated 8 months ago
- Situational Awareness script to identify how and where to run implants☆49Updated 5 months ago
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆23Updated last month
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated last year
- A pure C version of SymProcAddress☆27Updated last year
- in-process powershell runner for BRC4☆45Updated last year
- A repository with my code snippets for research/education purposes.☆50Updated last year
- Tool to obtain hash using MS-SNTP for user accounts☆22Updated 3 months ago
- Cortex EDR Ransomware protection Bypass☆21Updated 3 months ago
- Brief writeup of post exploitation methodologies.☆18Updated last year
- ☆37Updated 2 months ago
- Docker container for running CobaltStrike 4.10☆37Updated 7 months ago
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆41Updated 9 months ago
- 「⚙️」Detect which native Windows API's (NtAPI) are being hooked☆38Updated 5 months ago
- PowerShell script to generate ShellCode in various formats☆41Updated 7 months ago
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆75Updated 2 months ago
- Make an Linux Kernel rootkit visible again.☆51Updated 2 months ago
- Section-based payload obfuscation technique for x64☆59Updated 9 months ago
- Construct the payload at runtime using an array of offsets☆63Updated 10 months ago
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆34Updated 5 months ago
- ☆22Updated 2 months ago
- Dumping LSASS Evaded Endpoint Security Solutions☆12Updated 2 months ago
- Impersonate Tokens using only NTAPI functions☆71Updated last month
- Enable or Disable TokenPrivilege(s)☆13Updated 11 months ago
- Windows Thread Pool Injection Havoc Implementation☆29Updated last year
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆40Updated 11 months ago
- Sliver extension to bypass UAC via cmstp written in rust☆27Updated 11 months ago
- ☆56Updated 5 months ago
- Launches a limited shell using PowerShell Runspaces with an optional AMSI Bypass. Does not invoke Powershell.exe☆13Updated last year