kindtime / winfilter
Winlogon and LSA Notification Password Filters
☆18Updated last year
Alternatives and similar repositories for winfilter:
Users that are interested in winfilter are comparing it to the libraries listed below
- LOCAL AND REMOTE HOOK msv1_0!SpAcceptCredentials from LSASS.exe and DUMP DOMAIN/LOGIN/PASSWORD IN CLEARTEXT to text file.☆114Updated 4 years ago
- ☆42Updated last year
- ☆14Updated 2 years ago
- An example of COM hijacking using a proxy DLL.☆25Updated 3 years ago
- Upsilon execute shellcode with syscalls - no API like NtProtectVirtualMemory is used☆92Updated 3 years ago
- Injects shellcode into remote processes using direct syscalls☆74Updated 4 years ago
- ☆80Updated 2 years ago
- Bypass UAC elevation on Windows 8 (build 9600) & above.☆54Updated 2 years ago
- Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH☆44Updated 3 years ago
- ☆37Updated 3 years ago
- ☆50Updated 4 years ago
- Get your data from the resource section manually, with no need for windows apis☆56Updated 2 months ago
- A simple dumper as FreshyCalls' PoC. That's what's trendy, isn't it? ¯\_( ツ)_/¯☆39Updated 4 years ago
- An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities☆55Updated 2 years ago
- Your NTDLL vaccine from modern direct syscall methods.☆35Updated 2 years ago
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆52Updated 4 years ago
- A work in progress BOF/COFF loader in Rust☆46Updated last year
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- ☆39Updated 2 years ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- Beacon Object File allowing creation of Beacons in different sessions.☆78Updated 2 years ago
- Collection of Beacon Object Files (BOFs) for shells and lols☆113Updated 3 years ago
- Former Multi - Ring to Kernel To UserMode Transitional Shellcode For Remote Kernel Exploits☆28Updated 2 years ago
- Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.☆99Updated 2 years ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆39Updated last year