cbrnrd / malikethLinks
🗡️ A multi-user malleable C2 framework targeting Windows. Written in C++ and Python
☆45Updated last year
Alternatives and similar repositories for maliketh
Users that are interested in maliketh are comparing it to the libraries listed below
Sorting:
- a demo module for the kaine agent to execute and inject assembly modules☆38Updated 9 months ago
- shell code example☆49Updated last month
- ☆32Updated 6 months ago
- Shellcode Loader Utilizing ETW Events☆63Updated 3 months ago
- converts sRDI compatible dlls to shellcode☆29Updated 5 months ago
- ForsHops☆53Updated 2 months ago
- Linker for Beacon Object Files☆116Updated this week
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆61Updated last year
- Mirage is a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆82Updated 4 months ago
- Get your data from the resource section manually, with no need for windows apis☆63Updated 8 months ago
- ☆23Updated 4 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 10 months ago
- Reimplementation of the KExecDD DSE bypass technique.☆48Updated 9 months ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆50Updated last year
- This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hol…☆70Updated last year
- Windows C++ Implant for Exploration C2☆31Updated 3 weeks ago
- Research into removing strings & API call references at compile-time (Anti-Analysis)☆27Updated last year
- Set the process mitigation policy for loading only Microsoft Modules , and block any userland 3rd party modules☆42Updated 2 years ago
- Section-based payload obfuscation technique for x64☆61Updated 10 months ago
- Simple ETW unhook PoC. Overwrites NtTraceEvent opcode to disable ETW at Nt-function level.☆47Updated last year
- Threadless shellcode injection tool☆65Updated 10 months ago
- Exploiting the KsecDD Windows driver through Server Silos☆72Updated 7 months ago
- Less sugar (entropy) for your binaries☆25Updated 3 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated 2 years ago
- Windows AppLocker Driver (appid.sys) LPE☆62Updated 10 months ago
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆64Updated 2 years ago
- ☆99Updated last year
- A C# implementation that disables Windows Firewall bypassing UAC☆15Updated 8 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆59Updated 7 months ago
- Boilerplate to develop raw and truly Position Independent Code (PIC).☆51Updated 5 months ago