netero1010 / RDPHijack-BOF
Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.
☆297Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for RDPHijack-BOF
- A BOF to automate common persistence tasks for red teamers☆266Updated last year
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆292Updated 2 years ago
- Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE☆201Updated last year
- ☆213Updated 8 months ago
- Dumping LSASS with a duplicated handle from custom LSA plugin☆199Updated 2 years ago
- Execute shellcode from a remote-hosted bin file using Winhttp.☆225Updated last year
- CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking☆216Updated last year
- Execute shellcode files with rundll32☆184Updated 9 months ago
- Fileless atexec, no more need for port 445☆327Updated 7 months ago
- ☆207Updated 6 months ago
- An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are a…☆120Updated 2 years ago
- A beacon object file implementation of PoolParty Process Injection Technique.☆324Updated 11 months ago
- COM Hijacking VOODOO☆257Updated 8 months ago
- A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.☆124Updated last year
- A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.☆441Updated 7 months ago
- Credential Guard Bypass Via Patching Wdigest Memory☆310Updated last year
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆251Updated last year
- CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process inject…☆227Updated last year
- Terminate AV/EDR Processes using kernel driver☆338Updated last year
- Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS☆173Updated 2 years ago
- Pass the Hash to a named pipe for token Impersonation☆294Updated 11 months ago
- Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus☆226Updated 2 years ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆366Updated 5 months ago
- PoC to coerce authentication from Windows hosts using MS-WSP☆225Updated last year
- Bypass Detection By Randomising ROR13 API Hashes☆133Updated 2 years ago
- A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk☆428Updated 4 months ago
- Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.☆147Updated 2 years ago
- Weaponized HellsGate/SigFlip☆194Updated last year
- MSSQL Database Attacker tool☆185Updated 2 years ago