Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.
☆157Feb 14, 2026Updated 2 months ago
Alternatives and similar repositories for ClickOnceBlobber
Users that are interested in ClickOnceBlobber are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆49Dec 5, 2025Updated 4 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆175Sep 3, 2025Updated 7 months ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Apr 14, 2025Updated last year
- ☆19Sep 1, 2025Updated 7 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆127Jan 29, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- wtftp.py is a tool to attack Microsoft Deployment Toolkit (MDT) and Windows Deployment Services (WDS).☆33Jan 22, 2026Updated 2 months ago
- AppLocker-Based EDR Neutralization☆334Dec 19, 2025Updated 4 months ago
- adws enumeration bof☆170Feb 16, 2026Updated 2 months ago
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆111Jan 26, 2026Updated 2 months ago
- Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)☆136Oct 23, 2025Updated 5 months ago
- ☆65Mar 15, 2024Updated 2 years ago
- ☆19Dec 18, 2024Updated last year
- Cobalt Strike BOF☆55Dec 10, 2025Updated 4 months ago
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆25Mar 19, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A python script that automates a C2 Profile build☆48Dec 14, 2025Updated 4 months ago
- Commandline spoofing on Windows☆101Nov 25, 2025Updated 4 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆171Jan 12, 2026Updated 3 months ago
- Offensive Assembly code snippets.☆13Jul 12, 2023Updated 2 years ago
- The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver☆43Mar 13, 2026Updated last month
- A proof-of-concept to demonstrate randomized execution paths and their impact on call stack signatures — ideal for EDR testing, behavior-…☆24Jan 17, 2026Updated 3 months ago
- Leak NTLM via Website tab in teams via MS Office☆79Mar 28, 2024Updated 2 years ago
- Custom Amsi Bypass by patching AmsiOpenSession function in amsi.dll☆51Jun 16, 2025Updated 10 months ago
- ☆138Nov 17, 2025Updated 5 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A C# implementation of dumping credentials from Windows Credential Manager☆62Sep 23, 2023Updated 2 years ago
- ☆95Apr 7, 2026Updated last week
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated 7 months ago
- a C# implementation for a shellcode loader that capable to bypass Cortex XDR and Sophos EDR.☆92May 24, 2025Updated 10 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆349Mar 21, 2026Updated 3 weeks ago
- Project for generating and identifying deceptive LNK files.☆322Mar 8, 2026Updated last month
- ☆124May 12, 2021Updated 4 years ago
- Windows Session Hijacking via COM☆346Dec 13, 2025Updated 4 months ago
- COFF file (BOF) for managing Kerberos tickets.☆322Jul 2, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A PE parser written in C++ which does not uses OOP. Helpful if you want to learn about PE parsing.☆18Apr 10, 2023Updated 3 years ago
- ☆234Jun 10, 2025Updated 10 months ago
- Adaptix C2 agent using Crystal Palace PIC linker and PICO module system☆74Mar 7, 2026Updated last month
- ☆43Apr 13, 2026Updated last week
- A C# utility for interacting with SCOM☆98Dec 2, 2025Updated 4 months ago
- load shellcode without P/D Invoke and VirtualProtect call.☆169Sep 2, 2025Updated 7 months ago
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆193Apr 14, 2024Updated 2 years ago