buldansec / EnableEFSLinks
Enable EFS service as low priv user (PE & BOF)
☆21Updated 7 months ago
Alternatives and similar repositories for EnableEFS
Users that are interested in EnableEFS are comparing it to the libraries listed below
Sorting:
- Calling the undocumented DPAPI RPC interface directly, no more calling public CryptUnprotectData!☆66Updated this week
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Updated 9 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆38Updated 6 months ago
- ☆51Updated 7 months ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆128Updated last week
- The most extensive collection of BOFs (Beacon Object Files) tailored for Red Teams using C++23☆23Updated 7 months ago
- Random BOFs for LDAP tradecraft☆72Updated 5 months ago
- converts sRDI compatible dlls to shellcode☆35Updated last year
- ☆50Updated 8 months ago
- ☆55Updated 8 months ago
- One WSL BOF to rule them all☆138Updated 3 weeks ago
- A small set of Beacon Object Files (BOFs) that I developed over the time with a Magic: The Gathering theme.☆16Updated 6 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆61Updated last month
- Local SYSTEM auth trigger for relaying - X☆155Updated 6 months ago
- ForsHops☆59Updated 10 months ago
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆60Updated last month
- Rust template/library for implementing your own COFF loader☆71Updated last year
- ☆100Updated last year
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75Updated last year
- ☆35Updated last year
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆43Updated 3 months ago
- ☆86Updated last year
- a BOF implementation of various registry persistence methods☆94Updated 2 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆120Updated 3 weeks ago
- A modern Rust implementation of the original Stardust project, providing a sophisticated 32/64-bit shellcode template that features posit…☆59Updated 10 months ago
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆75Updated 3 months ago
- Crystal Palace library for proxying Nt API calls via the Threadpool☆97Updated 3 months ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆48Updated 3 months ago
- Lateral Movement Bof with MSI ODBC Driver Install☆141Updated 4 months ago
- Threadless shellcode injection tool☆68Updated last year