mertdas / RedPersist
☆212Updated 7 months ago
Related projects ⓘ
Alternatives and complementary repositories for RedPersist
- A Tool that aims to evade av with binary padding☆135Updated 4 months ago
- Execute shellcode files with rundll32☆181Updated 9 months ago
- 🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.☆158Updated last year
- Leverage WindowsApp createdump tool to obtain an lsass dump☆141Updated last month
- Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege☆199Updated 11 months ago
- ☆163Updated last year
- Use ESC1 to perform a makeshift DCSync and dump hashes☆198Updated last year
- Terminate AV/EDR Processes using kernel driver☆336Updated last year
- ☆311Updated 11 months ago
- ☆207Updated 6 months ago
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆227Updated 4 months ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆262Updated this week
- Escalate Service Account To LocalSystem via Kerberos☆389Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆264Updated 3 months ago
- Evasive Golang Loader☆130Updated 3 months ago
- NoArgs is a tool designed to dynamically spoof and conceal process arguments while staying undetected. It achieves this by hooking into W…☆146Updated 6 months ago
- Different methods to get current username without using whoami☆172Updated 8 months ago
- Execute shellcode from a remote-hosted bin file using Winhttp.☆224Updated last year
- Kill AV/EDR leveraging BYOVD attack☆307Updated last year
- Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE☆200Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆364Updated 4 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆275Updated 3 months ago
- Fileless atexec, no more need for port 445☆325Updated 7 months ago
- Attempt at Obfuscated version of SharpCollection☆188Updated last month
- Weaponized HellsGate/SigFlip☆191Updated last year
- CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking☆215Updated last year
- Set of python scripts which perform different ways of command execution via WMI protocol.☆158Updated last year
- Repository contains psexec, which will help to exploit the forgotten pipe☆160Updated this week