lisandro-git / sandbox_evasionLinks
Sandbox evasion code snippets developped in Golang
☆19Updated 2 years ago
Alternatives and similar repositories for sandbox_evasion
Users that are interested in sandbox_evasion are comparing it to the libraries listed below
Sorting:
- Perform DCSync operation without mimikatz☆146Updated 7 months ago
- 🔎🪲 Malleable C2 profiles parser and assembler written in golang☆66Updated last year
- Bypass Detection By Randomising ROR13 API Hashes☆140Updated 3 years ago
- AV/EDR evasion via direct system calls.☆108Updated last year
- my learning case about windows☆21Updated 3 years ago
- Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.☆112Updated 4 years ago
- Dumping LSASS with a duplicated handle from custom LSA plugin☆201Updated 3 years ago
- A spin-off research project. Cobalt Strike x Notion collab 2022☆53Updated 3 years ago
- Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs☆126Updated 3 years ago
- Little program written in C# to bypass EDR hooks and dump the content of the lsass process☆61Updated 3 years ago
- Another Go Shellcode Loader using Windows APIs☆140Updated 3 years ago
- Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS☆184Updated 3 years ago
- Modular C2 framework aiming to ease post exploitation for red teamers.☆187Updated 3 years ago
- ☆65Updated 3 years ago
- A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.☆150Updated 3 years ago
- Pass the Hash to a named pipe for token Impersonation☆144Updated 4 years ago
- Perun's Fart (Slavic God's Luck). Another method for unhooking AV and EDR, this is my C# version.☆109Updated 3 years ago
- A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.☆140Updated 3 years ago
- BOF implementation of the research by @jonasLyk and the drafted PoC from @LloydLabs☆182Updated 3 years ago
- Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File☆201Updated 4 years ago
- A simple BOF that frees UDRLs☆120Updated 3 years ago
- DCSync Attack from Outside using Impacket☆115Updated 3 years ago
- Zipper, a CobaltStrike file and folder compression utility.☆221Updated 5 years ago
- Remove API hooks from a Beacon process.☆270Updated 3 years ago
- Load shellcode via HELLGATE, Rewrite hellgate with .net framework for learning purpose.☆16Updated 3 years ago
- Beacon Object File PoC implementation of KillDefender☆227Updated 3 years ago
- My CobaltStrike BOFS☆166Updated 2 years ago
- An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are a…☆135Updated 2 years ago
- Golang evasion tool, execute-assembly .Net file☆97Updated 3 years ago
- Read the contents of MS Word Documents using Cobalt Strike's Execute-Assembly☆117Updated 8 months ago