michaelbadichi / RunAsSystemLinks
☆33Updated 10 years ago
Alternatives and similar repositories for RunAsSystem
Users that are interested in RunAsSystem are comparing it to the libraries listed below
Sorting:
- ☆45Updated 7 years ago
- Inject .Net payloads into other .Net assemblies on disk☆61Updated 5 years ago
- ReaCOM has got a lot of tools to use and is related to component object model☆74Updated 5 years ago
- Automate AV evasion by calling AMSI☆87Updated 2 years ago
- Windows Installer Bypass using Rollback Script .rbs and .rbf - Race Condition☆22Updated 6 years ago
- ☆53Updated 7 years ago
- Ps1jacker is a tool for generating COM Hijacking payload.☆60Updated 8 months ago
- A tool for scanning registery key permissions. Find where non-admins can create symbolic links.☆45Updated 6 years ago
- GUI Application in C# to run and disassemble shellcode☆36Updated 8 years ago
- Synaptics Audio Driver LPE☆37Updated 6 years ago
- ☆54Updated 7 years ago
- ☆43Updated 6 years ago
- Create a Run registry key with direct system calls. Inspired by @Cneelis's Dumpert and SharpHide.☆77Updated 5 years ago
- ☆94Updated 6 years ago
- PoC for CVE-2020-1015☆39Updated 5 years ago
- few months old but better than nothing☆58Updated 3 years ago
- Python script to patch the reflective stub in a DLL☆24Updated 8 years ago
- Persistent through COM Hijacking☆22Updated 6 years ago
- ☆43Updated 6 years ago
- Gives context to a system. Uses EQGRP shadow broker leaked list to give some descriptions to processes.☆47Updated 8 years ago
- Experiments on the Windows Internals☆31Updated 6 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 4 years ago
- PoC: Prevent a debugger from attaching to managed .NET processes via a watcher process code pattern.☆32Updated 7 years ago
- Tool for injecting a "TCP Relay" managed assembly into an unmanaged process☆65Updated 6 years ago
- Proof of Concept code for CVE-2020-0728☆46Updated 5 years ago
- Extract the password of the current user from flow (keylogger, config file, ..) Use SSPI to get a valid NTLM challenge/response and test …☆59Updated 6 years ago
- Simple tool to use LsaManageSidNameMapping get LSA to add or remove SID to name mappings.☆23Updated 5 years ago
- A minimal safe version of mimikatz to only allow the export of non-exportable Windows certificates☆25Updated 7 years ago
- Remove individual lines from Windows Event Viewer Log (EVT) files☆44Updated 4 years ago
- ☆20Updated 6 years ago