crawl3r / FunWithAMSILinks
A repo to hold any bypasses I work on/study/whatever
☆19Updated 5 years ago
Alternatives and similar repositories for FunWithAMSI
Users that are interested in FunWithAMSI are comparing it to the libraries listed below
Sorting:
- C# .NET Assembly for interacting with File Object DACLs☆46Updated 5 years ago
- I used this to see if an EDR is running in Safe Mode☆36Updated 4 years ago
- C# port of LogServiceCrash☆46Updated 5 years ago
- SharpBuster is a C# implementation of a directory brute forcing tool. It's designed to be used via Cobalt Strike's execute-assembly and s…☆63Updated 5 years ago
- quick 'n dirty poc based on PoC windows auth prompt in c# based on https://gist.githubusercontent.com/mayuki/339952/raw/2c36b735bc51861a3…☆31Updated 5 years ago
- .Net Assembly to block ETW telemetry in current process☆81Updated 5 years ago
- A script that can be deployed to Azure App for C2 / Proxy / Redirector☆41Updated 6 years ago
- Send message on Telegram when you get a new Cobalt Strike beacon☆21Updated 6 years ago
- Bypass AMSI and Defender using Ordinal Values☆41Updated 5 years ago
- Aggressor Script to Execute Assemblies from Github☆70Updated 5 years ago
- C# wrapper for ligolo☆17Updated 4 years ago
- ☆73Updated 4 years ago
- Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.☆67Updated 5 years ago
- C# application that allows you to quick run SSH commands against a host or list of hosts☆42Updated 5 years ago
- My musings with C#☆28Updated 3 years ago
- Helper script for mangling CS payloads☆51Updated 6 years ago
- Using "svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc" as trigger☆58Updated 5 years ago
- .NET 4.0 Scheduled Job Lateral Movement☆90Updated 5 years ago
- ☆35Updated 8 years ago
- SharpDir is a simple code set to search both local and remote file systems for files and is compatible with Cobalt Strike.☆29Updated 6 years ago
- Cobalt Strike cna script for randomized argument spoofing☆51Updated 6 years ago
- PoC to interact with local/remote registry hives through WMI☆87Updated 5 years ago
- Playing around with token manipulation in C#.☆29Updated 6 years ago
- Initial Commit of Coresploit☆57Updated 4 years ago
- CobaltStrike AggressorScripts for the lazy☆10Updated 3 years ago
- A simplified version of DotNetToJScript to create a JScript file which loads a .NET v2 assembly from memory.☆46Updated 4 years ago
- Credential Dumper☆79Updated 5 years ago
- Suite of Shellcode Running Utilities☆114Updated 5 years ago
- AMSI Bypass Via the Heap☆107Updated 5 years ago
- CobaltStrike Aggressor Script to utilise FuzzySec's Windows Notification Framework Research to Spawn a Shell under Explorer.exe☆16Updated 6 years ago