decoder-it / TokenStealerLinks
☆163Updated 2 years ago
Alternatives and similar repositories for TokenStealer
Users that are interested in TokenStealer are comparing it to the libraries listed below
Sorting:
- NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into W…☆155Updated last year
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆149Updated last year
- Documents Exfiltration project for fun and educational purposes☆145Updated 2 years ago
- Execute shellcode files with rundll32☆214Updated 2 years ago
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year
- 「💀」Proof of concept on BYOVD attack☆165Updated last year
- Leverage WindowsApp createdump tool to obtain an lsass dump☆153Updated last year
- A variation of ProcessOverwriting to execute shellcode on an executable's section☆148Updated 2 years ago
- Set of python scripts which perform different ways of command execution via WMI protocol.☆165Updated 2 years ago
- Terminate AV/EDR leveraging BYOVD attack☆104Updated 10 months ago
- Evasive Golang Loader☆137Updated last year
- Windows Persistence IT-Security☆109Updated 10 months ago
- Create Anti-Copy DRM Malware☆71Updated last year
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆213Updated last year
- Port of Cobalt Strike's Process Inject Kit☆190Updated last year
- Automated .NET AppDomain hijack payload generation☆129Updated last year
- PoC for dumping and decrypting cookies in the latest version of Microsoft Teams☆132Updated 2 years ago
- Lateral Movement☆125Updated 2 years ago
- random code snippets, useful for getting started☆123Updated 2 months ago
- Remotely Enumerate sessions using undocumented Windows Station APIs☆118Updated last year
- WTSImpersonator utilizes WTSQueryUserToken to steal user tokens by abusing the RPC Named Pipe "\\pipe\LSM_API_service"☆122Updated last year
- Local & remote Windows DLL Proxying☆170Updated last year
- Abuse leaked token handles.☆134Updated 2 years ago
- Command and Control (C2) framework☆132Updated 8 months ago
- SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the proce…☆153Updated 6 months ago
- A modification to fortra's CVE-2023-28252 exploit, compiled to exe☆54Updated 2 years ago
- Cobalt Strike + Brute Ratel C4 Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique☆158Updated 2 years ago
- ☆169Updated last year
- ☆137Updated 2 years ago
- Weaponized HellsGate/SigFlip☆204Updated 2 years ago