last-byte / HppDLL
Source code for HppDLL - local password dumping using MsvpPasswordValidate hooks
☆1Updated 3 years ago
Related projects: ⓘ
- MiniDumpWriteDump behavior modification hook☆49Updated 3 years ago
- A simple COM server which provides a component to run shellcode☆131Updated 4 years ago
- .NET 4.0 Scheduled Job Lateral Movement☆86Updated 4 years ago
- ☆113Updated this week
- ☆90Updated 2 years ago
- Yet another LSASS dumper☆77Updated 3 years ago
- ☆88Updated this week
- C++ implant that interfaces with a SK8PARK server☆47Updated 3 years ago
- ☆53Updated 2 years ago
- C# PoC implementation for bypassing AMSI via in memory patching☆66Updated 4 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆74Updated 4 years ago
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆121Updated 3 years ago
- PoC to interact with local/remote registry hives through WMI☆81Updated 4 years ago
- C# Shellcode Runner to execute shellcode via CreateRemoteThread and SetThreadContext to evade Get-InjectedThread☆119Updated 5 years ago
- ☆37Updated this week
- SharpTask is a simple code set to interact with the Task Scheduler service api and is compatible with Cobalt Strike.☆87Updated 3 years ago
- AMSI Bypass Via the Heap☆105Updated 3 years ago
- Port of Invoke-Excel4DCOM☆100Updated 4 years ago
- juicypotato for win10 > 1803 & win server 2019☆95Updated 3 years ago
- Initial Commit of Coresploit☆55Updated 2 years ago
- Suite of Shellcode Running Utilities☆105Updated 4 years ago
- ☆69Updated 2 years ago
- ☆65Updated 3 years ago
- C# POC code for the SessionEnv dll hijack by utilizing called functions of TSMSISrv.dll☆58Updated 5 years ago
- ☆48Updated this week
- Aggressor Script to Execute Assemblies from Github☆66Updated 3 years ago
- Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.☆67Updated 3 years ago
- A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from …☆83Updated 4 years ago
- ☆73Updated this week
- quick 'n dirty poc based on PoC windows auth prompt in c# based on https://gist.githubusercontent.com/mayuki/339952/raw/2c36b735bc51861a3…☆31Updated 4 years ago