dis0rder0x00 / ParentProcessManipulation-LNKLinks
Using LNK files and user input simulation to start processes under explorer.exe
☆25Updated 9 months ago
Alternatives and similar repositories for ParentProcessManipulation-LNK
Users that are interested in ParentProcessManipulation-LNK are comparing it to the libraries listed below
Sorting:
- BypassCredGuard CS BOF☆42Updated 5 months ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆49Updated 3 weeks ago
- An advanced utility for converting Windows Portable Executable (PE) files to position-independent code (PIC) shellcode. It enables execut…☆54Updated 4 months ago
- Bypassing Amsi using LdrLoadDll☆45Updated 6 months ago
- ☆71Updated last year
- Tool to bypass LSA Protection (aka Protected Process Light)☆54Updated 6 months ago
- ☆44Updated 2 months ago
- ☆30Updated 3 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆51Updated last year
- EmbedExeLnk by x86matthew modified by d4rkiZ☆42Updated 2 years ago
- ☆96Updated 10 months ago
- Modified versions of the Cobalt Strike Process Injection Kit☆97Updated last year
- CVE-2024-40711-exp☆42Updated 9 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆42Updated 9 months ago
- ☆52Updated 6 months ago
- Cobalt Strike Beacon Object File (BOF) that uses CredUIPromptForWindowsCredentials API to invoke credential prompt☆20Updated 2 years ago
- ☆47Updated last week
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆46Updated 2 years ago
- Sliver agent rewritten in C++☆45Updated 10 months ago
- ProcExp Driver (Ab)use☆22Updated 2 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆84Updated 2 years ago
- Library of BOFs to interact with SQL servers☆22Updated 3 months ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆58Updated 2 years ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆47Updated 4 months ago
- Golang implementation of @CCob's C# ThreadlessInject☆32Updated last year
- Less sugar (entropy) for your binaries☆28Updated 3 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆60Updated last year
- Attempting to Hook LSASS APIs to Retrieve Plaintext Credentials☆48Updated 2 months ago
- ☆81Updated last year