kargisimos / detenv
A small and portable Windows C library for sandbox detection
☆34Updated last year
Alternatives and similar repositories for detenv:
Users that are interested in detenv are comparing it to the libraries listed below
- a variety of tools,scripts and techniques developed and shared with different programming languages by 0xsp Lab☆62Updated 3 months ago
- ☆47Updated 2 years ago
- C++ Staged Shellcode Loader with Evasion capabilities.☆82Updated 5 months ago
- To audit the security of read-only domain controllers☆114Updated last year
- Duplicate not owned Token from Running Process☆72Updated last year
- Winsocket for Cobalt Strike.☆98Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- in-process powershell runner for BRC4☆44Updated last year
- Secretsdump C# version only supporting local (live) operation☆49Updated last year
- Exploit for CVE-2023-27532 against Veeam Backup & Replication☆108Updated 2 years ago
- ☆54Updated 4 months ago
- RCE PoC for Empire C2 framework <5.9.3☆26Updated last year
- ☆54Updated 5 months ago
- ☆68Updated last year
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆40Updated last year
- A simple PoC of injection shellcode into a remote process and get the output using namepipe☆42Updated last year
- A repository with my code snippets for research/education purposes.☆50Updated last year
- Create Anti-Copy DRM Malware☆54Updated 7 months ago
- Tool to aid in dumping LSASS process remotely☆38Updated 8 months ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆46Updated 2 months ago
- Windows Persistence Toolkit in C#☆36Updated 2 years ago
- Modified versions of the Cobalt Strike Process Injection Kit☆93Updated last year
- ☆79Updated 11 months ago
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆40Updated 9 months ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆74Updated 2 years ago
- ☆35Updated 3 months ago
- lsassdump via RtlCreateProcessReflection and NanoDump☆80Updated 5 months ago
- ☆81Updated 10 months ago
- Enumerate information from NTLM authentication enabled web endpoints 🔎☆35Updated last year
- Run Cobalt Strike BOFs in Brute Ratel C4!☆63Updated 2 months ago