dosxuz / TradecraftImrprovementView external linksLinks
This repository will contain source codes from the Tradecraft improvement blog series
☆14Mar 27, 2025Updated 10 months ago
Alternatives and similar repositories for TradecraftImrprovement
Users that are interested in TradecraftImrprovement are comparing it to the libraries listed below
Sorting:
- ☆10Updated this week
- ☆11Feb 12, 2023Updated 3 years ago
- all random stuff that dont warrant a seperate repo☆12Sep 2, 2022Updated 3 years ago
- Launches a limited shell using PowerShell Runspaces with an optional AMSI Bypass. Does not invoke Powershell.exe☆13Dec 11, 2023Updated 2 years ago
- A (small) filesystem stored in the browser's LocalStorage☆12Oct 17, 2018Updated 7 years ago
- demo unhooking functions in ntdll☆28Jul 15, 2025Updated 7 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆49Mar 10, 2025Updated 11 months ago
- Data EXfiltration TestER☆21Aug 28, 2019Updated 6 years ago
- Bypassing Amsi using LdrLoadDll☆47Jan 8, 2025Updated last year
- WebView2 Wrapper☆39Dec 29, 2025Updated last month
- A driver loader for Windows NT using NtLoadDriver()☆24Aug 30, 2015Updated 10 years ago
- A C++ PoC implementation for enumerating Windows Fibers directly from memory☆21May 11, 2024Updated last year
- ☆56Updated this week
- ☆58Feb 16, 2025Updated last year
- C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)☆25Mar 7, 2023Updated 2 years ago
- Executing Kernel Routines via Syscall Table Hijack (Kernel Code Execution)☆57Jun 15, 2025Updated 8 months ago
- Python tool to find vulnerable AD object and generating csv report☆26Jul 4, 2022Updated 3 years ago
- Threadless shellcode injection tool☆68Aug 5, 2024Updated last year
- Payload Generation Workflow☆40Jul 18, 2025Updated 6 months ago
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆50Jul 6, 2025Updated 7 months ago
- Just another ntdll unhooking using Parun's Fart technique☆76Feb 15, 2023Updated 3 years ago
- Things i do because i saw it on twitter on a weekend☆58Jul 20, 2025Updated 6 months ago
- GetModuleHandle (via PEB) and GetProcAddress (via EAT) like☆32Feb 7, 2022Updated 4 years ago
- Check if your AV/EDR does inline hooking, displays the hooked functions and allows you to compare them with the original ones.☆36Apr 24, 2025Updated 9 months ago
- JS,CSS,HTML formatter for vscode☆50Jul 27, 2021Updated 4 years ago
- Demonstration of Early Bird APC Injection - MITRE ID T1055.004☆35Oct 31, 2023Updated 2 years ago
- A PoC tool for exploiting leaked process and thread handles☆32Feb 13, 2024Updated 2 years ago
- Indirect-Shellcode-Executor expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory discovered b…☆82Nov 15, 2025Updated 3 months ago
- ☆30Nov 7, 2022Updated 3 years ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Aug 5, 2024Updated last year
- Lateral Movement☆125Nov 14, 2023Updated 2 years ago
- A C# Tool to find left over pentest data for use in your pentest or redteam op. Blue could maybe use to find files to cleanup☆38Sep 14, 2023Updated 2 years ago
- Stealthy Loader-cum-dropper/stage-1/stager targeting Windows10☆37Nov 5, 2022Updated 3 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆41Jul 9, 2023Updated 2 years ago
- BIXI is a fast, stable, and powerful DDoS tool designed for efficiency. It supports multiple protocols including TCP, UDP, ICMP, HTTP, an…☆10Apr 9, 2025Updated 10 months ago
- BypassIT is a framework for covert malware delivery and post-exploitation using AutoIT for red / blue team self assessment.☆45Jul 6, 2025Updated 7 months ago
- Writing Nimless Nim - Slides and source for BSIDESKC 2024 talk.☆85Jul 11, 2025Updated 7 months ago
- JavaScript/Node.js Web Converter from image to Minecraft blocks.☆81Jul 30, 2023Updated 2 years ago
- Reflective DLL Injection Made Bella☆248Jan 6, 2025Updated last year