leftp / BackupCreds
A C# implementation of dumping credentials from Windows Credential Manager
☆56Updated last year
Alternatives and similar repositories for BackupCreds:
Users that are interested in BackupCreds are comparing it to the libraries listed below
- C# Tool to interact with MS Exchange based on MS docs☆99Updated 2 years ago
- Bypassing Amsi using LdrLoadDll☆32Updated 3 weeks ago
- PoC to self-delete a binary in C#☆29Updated 11 months ago
- C# Port of LdapRelayScan☆78Updated 2 years ago
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆132Updated 4 months ago
- Cobalt Strike BOF for quser.exe implementation using Windows API☆83Updated last year
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆72Updated 4 years ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆68Updated 8 months ago
- ☆127Updated last year
- Tool for playing with Windows Access Token manipulation.☆53Updated 2 years ago
- My implementation of Halo's Gate technique in C#☆53Updated 2 years ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- ☆37Updated 2 years ago
- Click Once + App Domain☆63Updated last year
- A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation☆15Updated last month
- GPOAnalyzer is a tool designed to assist in parsing domain Group Policy Object (GPO) files located in the SYSVOL directory.☆23Updated 7 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆78Updated 2 years ago
- ☆35Updated 2 years ago
- Tool to aid in dumping LSASS process remotely☆38Updated 6 months ago
- ☆25Updated 2 months ago
- Lateral Movement via the .NET Profiler☆77Updated 2 months ago
- SharpElevator is a C# implementation of Elevator for UAC bypass. This UAC bypass was originally discovered by James Forshaw and publishe…☆50Updated 2 years ago
- Enumerate information from NTLM authentication enabled web endpoints 🔎☆35Updated last year
- I have documented all of the AMSI patches that I learned till now☆69Updated last year
- Quick python script to replace the NtAPI functions within SysWhispers' assembly and header files with random strings☆26Updated 2 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆44Updated last year
- C# havoc implant☆96Updated last year
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆71Updated last year