d4rckh / WindowsPotatoes
A list of windows potatoes!
☆25Updated 3 years ago
Alternatives and similar repositories for WindowsPotatoes:
Users that are interested in WindowsPotatoes are comparing it to the libraries listed below
- ☆55Updated 3 years ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆67Updated 10 months ago
- D/Invoke implementation in Nim☆101Updated 2 years ago
- RDPThief donut shellcode inject into mstsc☆85Updated 3 years ago
- Grab Firefox post requests by hooking PR_Write function from nss3.dll module using trampoline hook to get passwords and emails of users☆42Updated 2 years ago
- Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic lo…☆25Updated 2 years ago
- ☆58Updated 3 years ago
- ☆26Updated 3 years ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆90Updated 2 years ago
- It's pointy and it hurts!☆125Updated 2 years ago
- Overwrite a process's recovery callback and execute with WER☆103Updated 3 years ago
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.☆62Updated 3 years ago
- Rewrote HellsGate in C# for fun and learning☆86Updated 3 years ago
- DInvisibleRegistry☆82Updated 4 years ago
- Simple DLL that add a user to the local Administrators group☆77Updated 3 years ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆113Updated last year
- ☆39Updated 4 years ago
- Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processes☆105Updated 2 years ago
- MiniDumpWriteDump behavior modification hook☆50Updated 4 years ago
- A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket☆55Updated 4 years ago
- NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs☆94Updated 2 years ago
- .NET project for installing Persistence☆64Updated 3 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆93Updated 3 years ago
- Perun's Fart (Slavic God's Luck). Another method for unhooking AV and EDR, this is my C# version.☆107Updated 3 years ago
- Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog …☆80Updated last year
- ☆62Updated 2 years ago
- AMSI Bypass Via the Heap☆107Updated 4 years ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆94Updated 3 years ago
- A recreation of the "Nobelium" malware based on Microsofts Malware analysis - Part 1: PDF2Pwn☆101Updated 2 years ago