mlcsec / FormThief
Spoofing desktop login applications with WinForms and WPF
☆171Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for FormThief
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆167Updated 8 months ago
- ☆132Updated 5 months ago
- Patch AMSI and ETW☆230Updated 6 months ago
- GregsBestFriend process injection code created from the White Knight Labs Offensive Development course☆171Updated last year
- Patching AmsiOpenSession by forcing an error branching☆143Updated last year
- ☆217Updated last year
- Execute shellcode files with rundll32☆181Updated 9 months ago
- ☆265Updated last year
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆190Updated 4 months ago
- .NET/PowerShell/VBA Offensive Security Obfuscator☆87Updated 6 months ago
- ☆139Updated 4 months ago
- Hide your P/Invoke signatures through other people's signed assemblies☆200Updated 7 months ago
- ☆112Updated last year
- Retrieve and display information about active user sessions on remote computers. No admin privileges required.☆164Updated 2 months ago
- Extracting NetNTLM without touching lsass.exe☆223Updated 11 months ago
- CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administr…☆174Updated 10 months ago
- Weaponized HellsGate/SigFlip☆191Updated last year
- PoC to coerce authentication from Windows hosts using MS-WSP☆222Updated last year
- ☆142Updated last year
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆101Updated last year
- Generate Shellcode Loaders & Injects☆152Updated last year
- Run Your Payload Without Running Your Payload☆176Updated 2 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆134Updated 5 months ago
- ☆160Updated 2 years ago
- My implementation of the GIUDA project in C++☆155Updated last year
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆166Updated last year
- A collection of Cobalt Strike Aggressor scripts.☆84Updated 2 years ago
- reflectively load and execute PEs locally and remotely bypassing EDR hooks☆148Updated 10 months ago
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆144Updated this week