nccgroup / mnemosyne
A Generic Windows Memory Scraping Tool
☆70Updated 7 years ago
Alternatives and similar repositories for mnemosyne:
Users that are interested in mnemosyne are comparing it to the libraries listed below
- Open Source Office Malware Generation & Polymorphic Engine for Red Teams and QA testing☆95Updated 7 years ago
- ☆113Updated 7 years ago
- Another Repo of Malware. Enjoy. <3☆60Updated 5 years ago
- Some sample code from my Zero Nights 2017 presentation.☆62Updated 7 years ago
- ☆59Updated 5 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics☆85Updated 7 years ago
- Loads the AutoIt DLL and PowerShell assemblies into memory and executes the specified keystrokes☆61Updated 7 years ago
- An automated collection and analysis of malware from my honeypots.☆25Updated 7 years ago
- x86-64 Windows shellcode that recreates the Jurassic Park hacking scene (Ah, ah, ah... you didn't' say the magic word!)☆83Updated 4 years ago
- NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements☆96Updated 7 years ago
- MS17-012 - COM Session Moniker EoP Exploit running within MSBuild.exe☆59Updated 7 years ago
- Reflective Polymorphism☆104Updated 6 years ago
- Resolves DLL API entrypoints for a process w/ remote query capabilities.☆54Updated 7 years ago
- ☆51Updated 6 years ago
- POC for IAT Parsing Payloads☆47Updated 8 years ago
- PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels☆66Updated 9 years ago
- ☆68Updated 7 years ago
- PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.☆148Updated 5 years ago
- ☆97Updated 8 years ago
- Mixing up CVE and MS like a pro☆24Updated 7 years ago
- A set of demos and a PowerShell module to interact with DotNetInterop.☆67Updated 6 years ago
- A repository of some of my Windows 10 Device Guard Bypasses☆134Updated 7 years ago
- Tiny payload for transfer via LOKI - Provides high speed Virtual Channel two way file transfer capabilities☆26Updated 9 years ago
- POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's s…☆103Updated 7 years ago
- ☆84Updated 9 years ago
- Environmental (and http) keying for scripting languages☆39Updated 6 years ago
- Scan web server for known webshell names and responses☆50Updated 8 years ago
- Make Windows LNK file with python (pylnk)☆66Updated 8 years ago
- An offensive Powershell console☆30Updated 9 years ago