Userland API Unhooker Project
☆111Apr 4, 2026Updated 4 months ago
Alternatives and similar repositories for Celeborn
Users that are interested in Celeborn are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Nim version of MDSec's Parallel Syscall PoC☆123Apr 4, 2026Updated 4 months ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆90Aug 26, 2021Updated 4 years ago
- A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.☆142Sep 24, 2021Updated 4 years ago
- A BOF.NET program to split a file into smaller chunks and email it via a specified SMTP relay.☆17Jun 24, 2021Updated 5 years ago
- A PoC project for embedding shellcode to Hint/Name Table☆114Apr 4, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆23May 28, 2021Updated 5 years ago
- UnhookMe is an universal Windows API resolver & unhooker addressing problem of invoking unmonitored system calls from within of your Red …☆348Jul 3, 2022Updated 4 years ago
- New UAC bypass for Silent Cleanup for CobaltStrike☆189Jul 14, 2021Updated 5 years ago
- Proof of concept - Covert Channel using Windows Filtering Platform (C#)☆21Aug 29, 2021Updated 4 years ago
- Encrypted PE Loader Generator☆546Apr 4, 2026Updated 4 months ago
- A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.☆19Jun 24, 2021Updated 5 years ago
- A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.☆297Aug 18, 2023Updated 3 years ago
- Remove API hooks from a Beacon process.☆283Sep 18, 2021Updated 4 years ago
- C# Implementation of the Hell's Gate VX Technique☆215Jun 30, 2020Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆123May 22, 2021Updated 5 years ago
- LoadLibrary for offensive operations☆31Dec 14, 2021Updated 4 years ago
- ☆100Sep 20, 2021Updated 4 years ago
- Project to check which Nt/Zw functions your local EDR is hooking☆202Mar 21, 2021Updated 5 years ago
- Executes position independent shellcode from an encrypted zip☆303Dec 22, 2020Updated 5 years ago
- C++ WinRM API via Reflective DLL☆145Sep 11, 2021Updated 4 years ago
- A User Impersonation tool - via Token or Shellcode injection☆421May 21, 2022Updated 4 years ago
- OffensivePH - use old Process Hacker driver to bypass several user-mode access controls☆332Oct 9, 2021Updated 4 years ago
- A beacon generator using Cobalt Strike and a variety of tools.☆446Aug 10, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆31Aug 23, 2020Updated 5 years ago
- A simple PoC to demonstrate that is possible to write Non writable memory and execute Non executable memory on Windows☆52Jun 14, 2021Updated 5 years ago
- EarlyBird process hollowing technique (BOF) - Spawns a process in a suspended state, inject shellcode, hijack main thread with APC, and e…☆292Mar 8, 2023Updated 3 years ago
- ☆24Sep 26, 2021Updated 4 years ago
- DInvisibleRegistry☆82Nov 20, 2020Updated 5 years ago
- A proof-of-concept tool that attempts to retrieve the configuration from the memory dump of an F-Secure C3 Relay executable.☆16Jul 2, 2021Updated 5 years ago
- Assembly HellGate implementation that directly calls Windows System Calls and displays the PPID of the explorer.exe process☆108Mar 8, 2023Updated 3 years ago
- SharpHook is an offensive API hooking tool designed to catch various credentials within the API call.☆320Jul 1, 2021Updated 5 years ago
- This aggressor script uses a beacon's note field to indicate the health status of a beacon.☆143Sep 29, 2021Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Collection of beacon object files for use with Cobalt Strike to facilitate 🐚.☆187Feb 11, 2021Updated 5 years ago
- (Sim)ulate (Ba)zar Loader☆28Nov 15, 2020Updated 5 years ago
- Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions☆496Apr 1, 2021Updated 5 years ago
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆107Jan 3, 2021Updated 5 years ago
- PoC to demonstrate how CLR ETW events can be tampered.☆191Mar 26, 2020Updated 6 years ago
- ☆84Aug 26, 2024Updated last year
- POCs for Shellcode Injection via Callbacks☆415Feb 23, 2021Updated 5 years ago