christophetd / spoofing-office-macro
PoC of a VBA macro spawning a process with a spoofed parent and command line.
☆375Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for spoofing-office-macro
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆341Updated 4 years ago
- ☆462Updated last year
- Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.☆499Updated 4 years ago
- PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)☆321Updated 5 years ago
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆244Updated 4 years ago
- ☆347Updated 2 years ago
- Process Injection☆752Updated 3 years ago
- A VBA implementation of the RunPE technique or how to bypass application whitelisting.☆790Updated 4 years ago
- The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.☆465Updated 2 years ago
- Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.☆495Updated 5 years ago
- Aggressor scripts I've made for Cobalt Strike☆404Updated last year
- AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.☆384Updated 5 years ago
- Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely☆398Updated 2 years ago
- ☆257Updated last year
- ☆237Updated 6 years ago
- Toolbox containing research notes & PoC code for weaponizing .NET's DLR☆513Updated 2 years ago
- A modular C2 framework☆398Updated this week
- Evading WinDefender ATP credential-theft☆253Updated 4 years ago
- RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.☆328Updated last year
- Ps-Tools, an advanced process monitoring toolkit for offensive operations☆334Updated 3 years ago
- A Bind Shell Using the Fax Service and a DLL Hijack☆324Updated 4 years ago
- Obfuscate powershell scripts by replacing Function names, Variables and Parameters.☆511Updated last year
- Excel Macro Document Reader/Writer for Red Teamers & Analysts☆513Updated 2 years ago
- This is a PowerShell Empire launcher PoC using PrintDemon and Faxhell.☆198Updated 4 years ago
- Quick Malicious ClickOnceGenerator for Red Team☆246Updated 3 years ago
- A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.☆425Updated 2 years ago