SMB deny-share handle research tool. Lock files on an enterprise share with zero writes, zero encryption, and zero alerts in any behavioral defense. Standard user. One API call. No CVE.
☆139May 15, 2026Updated 2 months ago
Alternatives and similar repositories for GhostLock
Users that are interested in GhostLock are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago
- The tool is used to create a local webserver and force authenticate, which captures the logged in users NTLM v2 hash.☆16Feb 17, 2026Updated 5 months ago
- Automated Nim shellcode stager builder for Sliver C2 - cross-compiles a Windows evasion payload in one command. For authorized red team e…☆46Apr 12, 2026Updated 3 months ago
- ☆51Jul 12, 2026Updated last week
- Active Directory information dumper via ADWS for evasion purposes.☆274Jul 9, 2026Updated last week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Evasive loader for .NET Framework assemblies☆44May 14, 2026Updated 2 months ago
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jun 2, 2026Updated last month
- Activation Context Hijacking Evasion Tool☆295Jun 17, 2026Updated last month
- A BloodHound OpenGraph collector that models Windows local privilege escalation as interconnected attack paths.☆508Apr 26, 2026Updated 2 months ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆18May 22, 2026Updated last month
- Breakglass Intelligence — Detection rules, IOCs, and STIX bundles from threat intelligence investigations. YARA, Suricata, SIGMA, and KQL…☆19May 7, 2026Updated 2 months ago
- ASPX Web Shell with COFF Loader☆134Mar 10, 2026Updated 4 months ago
- A Dockerized build pipeline for custom Windows x64 shellcode☆55Dec 12, 2025Updated 7 months ago
- Windows named pipe hooking toolkit☆44Mar 20, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- RoguePlanet Windows Defender Vulnerability☆1,556Jun 9, 2026Updated last month
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆107Jun 5, 2026Updated last month
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆56Jun 17, 2026Updated last month
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆112Jun 22, 2026Updated 3 weeks ago
- An offensive toolkit for restless guests #DEFCON33☆60Aug 11, 2025Updated 11 months ago
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆162Updated this week
- Red Team Techniques & TTPs: AD, C2, SCADA, PrivEsc, Web Hacking, Buffer Overflow, WiFi.☆18Jul 2, 2026Updated 2 weeks ago
- RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.☆102Jul 14, 2026Updated last week
- ProxyWatch☆70Apr 25, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- poc it like it's hot☆840Jun 30, 2026Updated 2 weeks ago
- One WSL BOF to rule them all☆178Jan 14, 2026Updated 6 months ago
- Advanced Command and Control Framework for Authorized Red Team Operations☆57Mar 1, 2026Updated 4 months ago
- Just a nice little shellcode loader using unconventional methods to avoid using signatured APIs☆23Jul 11, 2025Updated last year
- PowerShell implementation for AD CS☆157Mar 2, 2026Updated 4 months ago
- ☆92Updated this week
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆857May 23, 2026Updated last month
- Golang Automation Framework for Cobalt Strike using the Rest API☆60Apr 10, 2026Updated 3 months ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆130Dec 28, 2025Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A modern GoPhish fork with improved tracking accuracy and smarter detection.☆94Feb 16, 2026Updated 5 months ago
- AppLocker-Based EDR Neutralization☆339Dec 19, 2025Updated 7 months ago
- 🔥📜 Forbidden collection of Red Team sorcery 📜🔥☆407Mar 23, 2026Updated 3 months ago
- Shellcode loader that hides payload within Egyptian hieroglyphic Unicode characters (U+13000 plane) to evade detection. It decodes the gl…☆15Nov 20, 2025Updated 8 months ago
- Shellcode packer for CTFs and pentest / red team exams aiming for AV evasion!☆151Apr 4, 2026Updated 3 months ago
- Decentralized C2 framework built on libp2p☆432Jun 16, 2026Updated last month
- In-depth reverse engineering of a suspected LockBit affiliate dropper, documenting shellcode loading, import polymorphism, and payload de…☆15Jan 24, 2026Updated 5 months ago