hlldz / Phant0m
Windows Event Log Killer
☆1,755Updated last year
Related projects ⓘ
Alternatives and complementary repositories for Phant0m
- Run PowerShell with rundll32. Bypass software restrictions.☆1,772Updated 3 years ago
- Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources☆1,481Updated last year
- Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing…☆1,532Updated last year
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆2,556Updated 3 months ago
- Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS☆1,401Updated 6 years ago
- PowerShell Pass The Hash Utils☆1,480Updated 5 years ago
- A little toolbox to play with Microsoft Kerberos in C☆1,428Updated 2 years ago
- SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader☆1,224Updated 5 years ago
- An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR☆2,197Updated 11 months ago
- A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.☆1,824Updated last month
- Run PowerShell command without invoking powershell.exe☆1,474Updated last year
- LSASS memory dumper using direct system calls and API unhooking.☆1,490Updated 3 years ago
- ☆1,406Updated last year
- Hide your Powershell script in plain sight. Bypass all Powershell security features☆1,105Updated 5 years ago
- Cmd.exe Command Obfuscation Generator & Detection Test Harness☆827Updated 6 years ago
- The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool…☆1,122Updated 3 years ago
- A tool to create a JScript file which loads a .NET v2 assembly from memory.☆1,240Updated 3 years ago
- HTA encryption tool for RedTeams☆1,371Updated 2 years ago
- A post exploitation framework designed to operate covertly on heavily monitored environments☆2,044Updated 3 years ago
- Extract credentials from lsass remotely☆2,057Updated last month
- Identifies the bytes that Microsoft Defender flags on.☆2,313Updated last year
- ☆1,400Updated last year
- SharpSploit is a .NET post-exploitation library written in C#☆1,749Updated 3 years ago
- ☆2,013Updated last year
- CACTUSTORCH: Payload Generation for Adversary Simulations☆995Updated 6 years ago
- SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, Supe…☆1,229Updated last year
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,400Updated last year
- A tool to elevate privilege with Windows Tokens☆1,022Updated last year
- The goal of this repository is to document the most common techniques to bypass AppLocker.☆1,917Updated last year
- PowerShell Runspace Post Exploitation Toolkit☆1,523Updated 5 years ago