claissg / remote_amsi_bypass
Kill AMSI in a remote process PoC
☆10Updated 6 years ago
Alternatives and similar repositories for remote_amsi_bypass:
Users that are interested in remote_amsi_bypass are comparing it to the libraries listed below
- ☆54Updated 6 years ago
- Bypass AMSI and Executing PowerShell scripts from C# - using CyberArk's method to bypass AMSI☆29Updated 4 years ago
- C# DCOM Execution☆18Updated 5 years ago
- Proof of concept of VMSA-2017-0012☆41Updated 7 years ago
- CobaltStrike Aggressor Script to utilise FuzzySec's Windows Notification Framework Research to Spawn a Shell under Explorer.exe☆15Updated 5 years ago
- Code that can be used to create/steal/manipulate token contexts in a program. Can be implemented into other C# projects.☆12Updated 6 years ago
- C# Implementation of Get-VaultCredential☆13Updated 6 years ago
- ☆11Updated 5 years ago
- A VBA implementation of the RunPE technique or how to bypass application whitelisting.☆13Updated 6 years ago
- Encrypted Shellcode Loader Generator☆22Updated 5 years ago
- ☆36Updated 5 years ago
- A repo to hold any bypasses I work on/study/whatever☆18Updated 4 years ago
- Windows Shellcode Testing Utility to Run Shellcode From A File☆12Updated 4 years ago
- ☆45Updated 6 years ago
- Takes raw hex shellcode (e.g. msfvenom hex format) from a cmd line arg, text file, or URL download and runs it.☆19Updated 6 years ago
- Miscellaneous C-Sharp projects for red team activities☆24Updated 2 years ago
- A minimal safe version of mimikatz to only allow the export of non-exportable Windows certificates☆25Updated 6 years ago
- ☆14Updated 5 years ago
- My musings with C#☆28Updated 2 years ago
- This tool is designed to simplify and automate the extraction and organization of useful data from Cobalt Strike logs.☆17Updated 5 years ago
- CobaltStrike AggressorScripts for the lazy☆10Updated 2 years ago
- Retrieve the IIS Application Pool Credentials. Relies on the WebAdministration PowerShell Module.☆13Updated 7 years ago
- Simple skeleton for a CPP DLL☆22Updated 5 years ago
- POC code to crash Windows Event Logger Service☆26Updated 4 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆30Updated 7 years ago