itm4n / Pentest-Windows
Windows internals and exploitation tricks
β93Updated last month
Alternatives and similar repositories for Pentest-Windows:
Users that are interested in Pentest-Windows are comparing it to the libraries listed below
- πΎDogwalk PoC (using diagcab file to obtain RCE on windows)β80Updated 2 years ago
- β61Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged processβ66Updated 6 months ago
- β25Updated 2 years ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flaggedβ86Updated 2 years ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog postβ88Updated 2 years ago
- β54Updated 3 years ago
- I have documented all of the AMSI patches that I learned till nowβ68Updated last year
- Bypass UAC on Windows 10/11 x64 using ms-settings DelegateExecute registry key.β78Updated 2 years ago
- β89Updated 2 years ago
- The program uses the Windows API functions to traverse through directories and locate DLL files with RWX sectionβ98Updated last year
- β38Updated 2 years ago
- .NET project for installing Persistenceβ64Updated 2 years ago
- Identify and exploit leaked handles for local privilege escalation.β106Updated last year
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.β61Updated 2 years ago
- Perun's Fart (Slavic God's Luck). Another method for unhooking AV and EDR, this is my C# version.β105Updated 3 years ago
- Cobalt Strike BOF that uses a custom ASM HalosGate & HellsGate syscaller to return a list of processesβ98Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.β39Updated last year
- β49Updated last year
- Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.β99Updated 2 years ago
- PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxyβ35Updated last year
- β39Updated 2 years ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged pβ¦β49Updated 2 years ago
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback funcβ¦β84Updated 2 years ago
- RDLL for Cobalt Strike beacon to silence sysmon processβ87Updated 2 years ago
- β68Updated 5 months ago
- Randomβ32Updated 2 years ago