A complete hands-on reference of 67 Windows persistence techniques used by real-world APT groups. Each technique includes MITRE ATT&CK TTP mapping, known threat actor attribution, attack commands, verification steps, and cleanup — organized from No-Admin to Admin level. Built for red teamers, malware analysts, and cybersecurity learners.
☆21Jun 2, 2026Updated 3 months ago
Alternatives and similar repositories for window-persistence-Privilege-Escalation
Users that are interested in window-persistence-Privilege-Escalation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- UAC Bypass using RequestTrace scheduled task☆28Jul 23, 2026Updated last month
- Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with C…☆18Apr 12, 2026Updated 5 months ago
- Tools for offensive security of NetBackup infrastructures☆48Jun 6, 2023Updated 3 years ago
- ADKAVEH - One PowerShell script for Active Directory discovery and safe attack simulation.☆38Sep 28, 2025Updated 11 months ago
- SafeHarbor revamped with Direct Syscalls using InlineWhispers3☆14Feb 16, 2026Updated 7 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Binary Ninja Plugins to work with Unpac.Me unpacking service☆13Apr 24, 2025Updated last year
- Okta Data Collector for BloodHound Community☆17Updated this week
- CVE-2025-26794: Blind SQL injection in Exim 4.98 (SQLite DBM)- exploit writeup☆14Mar 19, 2025Updated last year
- My solutions in Python for Corelan's Exploit Writing Tutorials☆12Jun 2, 2016Updated 10 years ago
- “A curated collection of OSINT tools, techniques, and resources based on personal notes and experiences.”☆27Sep 10, 2026Updated last week
- CVE-2026-45250: FreeBSD 14.4 setcred kernel buffer overflow (LPE)☆22Jul 23, 2026Updated last month
- Windfall - Unauthenticated RCE exploit chain for Windmill & Nextcloud Flow (CVE-2026-29059). Path traversal + credential leak + PostgreSQ…☆18Apr 7, 2026Updated 5 months ago
- ☆15Mar 27, 2026Updated 5 months ago
- Cross-platform syscall-powered implant & C2 — direct syscalls (Win), raw syscalls (Linux), HTTPS/DNS/ICMP channels. No winapi layer.☆55Sep 11, 2026Updated last week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Smuggling C2 comms through links previews☆18Jun 17, 2026Updated 3 months ago
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated 2 months ago
- This is a collection of Worms for educational purposes☆36Jul 17, 2025Updated last year
- Fullscreen Theme for Playnite☆19Jul 9, 2025Updated last year
- A PowerShell Module to create a Client and Server Named Pipe Server on Windows Systems☆11Aug 31, 2018Updated 8 years ago
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 7 months ago
- Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.☆102Sep 3, 2026Updated 2 weeks ago
- Offensive toolage collection for the Windows environment.☆25Dec 4, 2025Updated 9 months ago
- Shellcode loader that hides payload within Egyptian hieroglyphic Unicode characters (U+13000 plane) to evade detection. It decodes the gl…☆15Nov 20, 2025Updated 9 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A rust implementation of HackBrowserData☆17Oct 1, 2025Updated 11 months ago
- ADAttributeHound is an OpenGraph extension for BloodHound that exports Active Directory custom attributes as node properties.☆23Jun 18, 2026Updated 3 months ago
- A small collector to model out abusable Seamless Single Sign On edges☆15Feb 11, 2026Updated 7 months ago
- ☆14May 30, 2018Updated 8 years ago
- Defanged malware stages from the telnyx 4.87.1/4.87.2 PyPI supply chain compromise — WAV steganography, credential stealer, Windows persi…☆21Mar 29, 2026Updated 5 months ago
- ☆13Apr 1, 2021Updated 5 years ago
- CTF Writeups☆12Feb 25, 2023Updated 3 years ago
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆19May 27, 2026Updated 3 months ago
- A simple server to act as a Veeam "honeypot" providing alerting for network scans for Veeam services☆17Aug 31, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Educational PowerShell-based shellcode injection library.☆17Aug 2, 2026Updated last month
- CVE 2025 27237 Zabbix LPE proof of concept.☆19Jan 26, 2026Updated 7 months ago
- Performs a global AMSI bypass by patching amsi.dll in memory.☆20Oct 14, 2025Updated 11 months ago
- A basic python based tool for domain ℹ️ information gathering. I am working 💻 on collecting information related to domain whois, history…☆13Jan 11, 2026Updated 8 months ago
- Unique technique for bypassing AMSI☆18Dec 26, 2025Updated 8 months ago
- ☆16Aug 6, 2026Updated last month
- Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)☆51Aug 29, 2026Updated 3 weeks ago