dobin / ace-firefistLinks
Attack chain emulator. Write recipes for initial access easily
☆22Updated 10 months ago
Alternatives and similar repositories for ace-firefist
Users that are interested in ace-firefist are comparing it to the libraries listed below
Sorting:
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- A VSCode devcontainer for development of COFF files with batteries included.☆50Updated 2 years ago
- Python module for running BOFs☆79Updated last month
- Bunch of BOF files☆37Updated 6 months ago
- ☆47Updated 2 years ago
- macOS dylib stager☆36Updated 11 months ago
- Command Augmentation support for BOFs and .NET assemblies across agents☆37Updated this week
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆88Updated 3 years ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆23Updated 3 years ago
- Threadless Injection Payload Toolkit☆12Updated 2 years ago
- Dumping LSA secrets: a story about task decorrelation☆14Updated last year
- StealthGuardian is a middleware layer that can be combined with adversary simulation tools to verify the resistance, detection level and…☆20Updated last year
- Python3 rewrite of AsOutsider features of AADInternals☆59Updated 5 months ago
- RPC to WebClient startup☆53Updated 4 months ago
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆31Updated 3 years ago
- PoC XLL builder in Python/Nim☆49Updated 3 years ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆79Updated 2 years ago
- Click Once + App Domain☆64Updated 2 years ago
- Examples of various container types for Python and Golang☆15Updated 4 months ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆21Updated last month
- ☆88Updated 3 years ago
- ☆13Updated 10 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- in-process powershell runner for BRC4☆48Updated 2 years ago
- ☆60Updated 4 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆41Updated 2 years ago
- ☆64Updated 2 years ago
- ☆61Updated 2 years ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆36Updated 3 weeks ago
- Example of using Sleep to create better named pipes.☆41Updated 2 years ago