michaelbadichi / RunAsSystemLinks
☆33Updated 10 years ago
Alternatives and similar repositories for RunAsSystem
Users that are interested in RunAsSystem are comparing it to the libraries listed below
Sorting:
- ☆45Updated 7 years ago
- Automate AV evasion by calling AMSI☆87Updated 2 years ago
- A tool for scanning registery key permissions. Find where non-admins can create symbolic links.☆45Updated 6 years ago
- PoC: Prevent a debugger from attaching to managed .NET processes via a watcher process code pattern.☆32Updated 7 years ago
- Inject .Net payloads into other .Net assemblies on disk☆61Updated 6 years ago
- Synaptics Audio Driver LPE☆37Updated 6 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆74Updated 5 years ago
- ☆53Updated 7 years ago
- Windows Installer Bypass using Rollback Script .rbs and .rbf - Race Condition☆22Updated 6 years ago
- A minimal safe version of mimikatz to only allow the export of non-exportable Windows certificates☆26Updated 7 years ago
- ☆54Updated 7 years ago
- GUI Application in C# to run and disassemble shellcode☆36Updated 8 years ago
- InsecurePowerShellHost is a .NET Core host process for InsecurePowerShell, a version of PowerShell Core v6.0.0 with key security features…☆31Updated 7 years ago
- Proof of Concept code for CVE-2020-0728☆47Updated 5 years ago
- Remove individual lines from Windows Event Viewer Log (EVT) files☆44Updated 4 years ago
- ☆42Updated 6 years ago
- few months old but better than nothing☆58Updated 3 years ago
- Ps1jacker is a tool for generating COM Hijacking payload.☆60Updated 10 months ago
- Protects and logs suspicious and malicious usage of .NET CSC.exe and Runtime C# Compilation☆25Updated 7 years ago
- Use bitsadmin to maintain persistence and bypass Autoruns☆66Updated 8 years ago
- A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.☆100Updated 7 years ago
- PoC for CVE-2020-1015☆39Updated 5 years ago
- Extract the password of the current user from flow (keylogger, config file, ..) Use SSPI to get a valid NTLM challenge/response and test …☆59Updated 6 years ago
- Proof of concept of VMSA-2017-0012☆41Updated 8 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆45Updated 4 years ago
- A collection of tools to enumerate and analyse Windows DACLs☆109Updated 10 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆79Updated 5 years ago
- Gives context to a system. Uses EQGRP shadow broker leaked list to give some descriptions to processes.☆48Updated 8 years ago
- ☆33Updated 6 years ago
- Windows 10 Exploit☆30Updated 7 years ago