LOCAL AND REMOTE HOOK msv1_0!SpAcceptCredentials from LSASS.exe and DUMP DOMAIN/LOGIN/PASSWORD IN CLEARTEXT to text file.
☆121Jan 27, 2020Updated 6 years ago
Alternatives and similar repositories for LogonCredentialsSteal
Users that are interested in LogonCredentialsSteal are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Shellcode reflective DLL injection in Rust☆32May 3, 2026Updated 4 months ago
- Inject .Net payloads into other .Net assemblies on disk☆60Dec 12, 2019Updated 6 years ago
- A simple script to generate JScript code for calling Win32 API functions using XLM/Excel 4.0 macros via Excel.Application "ExecuteExcel4M…☆90Nov 9, 2019Updated 6 years ago
- ☆179Feb 3, 2021Updated 5 years ago
- PoC to demonstrate how CLR ETW events can be tampered.☆191Mar 26, 2020Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A quick tool for hiding a new process running shellcode.☆57Jun 10, 2020Updated 6 years ago
- .Net Assembly to block ETW telemetry in current process☆79May 14, 2020Updated 6 years ago
- Run Rubeus via Rundll32☆214Apr 25, 2020Updated 6 years ago
- A Bind Shell Using the Fax Service and a DLL Hijack☆334May 3, 2020Updated 6 years ago
- .NET 4.0 WinRM API Command Execution☆165Sep 11, 2020Updated 5 years ago
- Alternative C# Implementation tool to retrieve Active Directory Integrated DNS records with IP addresses☆49Aug 8, 2020Updated 6 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,661Jul 10, 2023Updated 3 years ago
- Zipper, a CobaltStrike file and folder compression utility.☆222Jan 18, 2020Updated 6 years ago
- Capture screenshots from .NET using .NET methods or Windows API calls☆66Mar 9, 2020Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Tool to create hidden registry keys.☆490Oct 23, 2019Updated 6 years ago
- Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.☆67Oct 3, 2020Updated 5 years ago
- Managed assembly shellcode generation☆281Mar 19, 2021Updated 5 years ago
- SharpClipHistory is a .NET application written in C# that can be used to read the contents of a user's clipboard history in Windows 10 st…☆199Jan 23, 2020Updated 6 years ago
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆272May 3, 2023Updated 3 years ago
- .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py☆614Feb 16, 2023Updated 3 years ago
- RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.☆330Jul 7, 2023Updated 3 years ago
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆465Mar 8, 2023Updated 3 years ago
- CobaltStrike Aggressor Script to utilise FuzzySec's Windows Notification Framework Research to Spawn a Shell under Explorer.exe☆16Jul 6, 2019Updated 7 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆107Jan 3, 2021Updated 5 years ago
- Create a minidump of the LSASS process from memory☆258Nov 2, 2022Updated 3 years ago
- Syscall BOF to arbitrarily add/detract process token privilege rights.☆68Jul 10, 2024Updated 2 years ago
- UAC Bypass By Abusing Kerberos Tickets☆514Aug 10, 2023Updated 3 years ago
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆345Jul 21, 2020Updated 6 years ago
- lateral movement techniques that can be used during red team exercises☆278Jan 13, 2020Updated 6 years ago
- Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load().☆216Mar 5, 2020Updated 6 years ago
- Allow a Go process to dynamically load .NET assemblies☆148Mar 28, 2020Updated 6 years ago
- Standalone version of my AES Powershell payload for Cobalt Strike.☆111Dec 27, 2019Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Dump the memory of a PPL with a userland exploit☆890Jul 24, 2022Updated 4 years ago
- Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS head…☆598Jul 26, 2021Updated 5 years ago
- Use to browse the share file by eas(Exchange Server ActiveSync)☆46Jun 28, 2020Updated 6 years ago
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆252Sep 26, 2020Updated 5 years ago
- Various Cobalt Strike BOFs☆788Oct 16, 2022Updated 3 years ago
- Extracting Clear Text Passwords from mstsc.exe using API Hooking.☆1,469Jul 20, 2024Updated 2 years ago
- Collection of Beacon Object Files☆639Nov 1, 2022Updated 3 years ago