nbuzydeb / sincon24_modern_redteamLinks
This is the Git repository for the Modern Red Teaming workshop given at SINCON2024.
☆12Updated last year
Alternatives and similar repositories for sincon24_modern_redteam
Users that are interested in sincon24_modern_redteam are comparing it to the libraries listed below
Sorting:
- BOF for C2 framework☆44Updated last year
- Sniffing files generator☆59Updated 8 months ago
- Proxy function calls through the thread pool with ease☆30Updated 8 months ago
- rust port of pspy with support for process monitoring over dbus☆35Updated 4 months ago
- Blog/Journal on how to backdoor VSCode extensions☆75Updated 4 months ago
- ☆26Updated 9 months ago
- malleable profile generator GUI for Havoc☆55Updated 2 years ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆56Updated 7 months ago
- Command Augmentation support for BOFs and .NET assemblies across agents☆36Updated 5 months ago
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆40Updated last year
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆17Updated 4 months ago
- Parser and reconciliation tooling for large Active Directory environments.☆33Updated 9 months ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆37Updated 6 months ago
- use python on windows with full submodule support without installation☆30Updated 9 months ago
- macOS dylib stager☆36Updated 9 months ago
- Docker container for running CobaltStrike 4.7 and above☆24Updated 8 months ago
- Unix Process hollowing in rust☆22Updated 11 months ago
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆89Updated 10 months ago
- ☆47Updated 2 years ago
- ☆26Updated 8 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- ☆19Updated 11 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆35Updated 5 months ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated 9 months ago
- Hunting and injecting RWX 'mockingjay' DLLs in pure nim☆59Updated 11 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆31Updated 7 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- Bunch of BOF files☆36Updated 4 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆76Updated 2 months ago
- Example of using Sleep to create better named pipes.☆41Updated 2 years ago