maninwire / nimLoader
load dumped csharp binaries as assemblies and launch them in memory
☆26Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for nimLoader
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- ☆35Updated 2 years ago
- ☆15Updated last month
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆33Updated last year
- Example of using Sleep to create better named pipes.☆41Updated last year
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆51Updated 4 years ago
- IOXIDResolver from AirBus Security/PingCastle☆45Updated 3 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆25Updated 3 years ago
- SharpReg is a simple code set to interact with the Remote Registry service api and is compatible with Cobalt Strike.☆26Updated 4 years ago
- A third-party Gopher Assassin for the Havoc Framework.☆44Updated 10 months ago
- WhoAmI by asking the LDAP service on a domain controller.☆58Updated 2 years ago
- Bunch of BOF files☆24Updated 9 months ago
- A .NET implementation to dump SAM, SYSTEM, SECURITY registry hives from a remote host☆38Updated 11 months ago
- ☆46Updated last year
- in-process powershell runner for BRC4☆37Updated last year
- ☆18Updated 2 years ago
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆30Updated 2 years ago
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 5 months ago
- A care package of useful bofs for red team engagments☆48Updated 2 years ago
- ☆24Updated 2 years ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- ☆19Updated 5 months ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged p…☆49Updated 2 years ago
- Windows x64 Process Injection via Ghostwriting with Dynamic Configuration☆27Updated 3 years ago
- Python3 rewrite of AsOutsider features of AADInternals☆35Updated 2 months ago
- Purple Team Dropper generator using open source templates.☆14Updated 5 months ago
- PoC MSI payload based on ASEC/AhnLab's blog post☆22Updated 2 years ago
- LSASS enumeration like pypykatz written in C-Lang☆20Updated 2 years ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆66Updated last year