last-byte / unDefender
☆146Updated this week
Related projects: ⓘ
- ☆150Updated this week
- C# version of MDSec's ParallelSyscalls☆138Updated 2 years ago
- Move CS beacon to GPU memory when sleeping☆212Updated 2 years ago
- Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL…☆160Updated last year
- Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs☆117Updated 2 years ago
- C++ WinRM API via Reflective DLL☆139Updated 3 years ago
- Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR☆146Updated 3 years ago
- ☆105Updated this week
- ☆140Updated last year
- Collection of beacon object files for use with Cobalt Strike to facilitate 🐚.☆164Updated 3 years ago
- AmsiScanBufferBypass using D/Invoke☆128Updated 3 years ago
- Exploring in-memory execution of .NET☆130Updated 2 years ago
- Shellcode injection POC using syscalls.☆116Updated 4 years ago
- Injects shellcode into remote processes using direct syscalls☆74Updated 3 years ago
- Proof of concept Beacon Object File (BOF) that attempts to detect userland hooks in place by AV/EDR☆94Updated 3 years ago
- Cobalt Strike User Defined Reflective Loader (UDRL). Check branches for different functionality.☆134Updated 2 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆169Updated last year
- Experiment on reproducing Obfuscate & Sleep☆136Updated 3 years ago
- Example code for using named pipe output with beacon ReflectiveDLLs☆108Updated 4 years ago
- Beacon Object File (BOF) for remote process injection via thread hijacking☆186Updated 3 years ago
- A simple COM server which provides a component to run shellcode☆131Updated 4 years ago
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆121Updated 3 years ago
- Evasive Process Hollowing Techniques☆132Updated 4 years ago
- Shellcode injector using direct syscalls☆116Updated 4 years ago
- Building and Executing Position Independent Shellcode from Object Files in Memory☆154Updated 3 years ago
- PoC to demonstrate how CLR ETW events can be tampered.☆184Updated 4 years ago
- ☆146Updated 4 years ago
- ☆100Updated this week
- Simple DLL that add a user to the local Administrators group☆74Updated 2 years ago