LOCAL AND REMOTE HOOK msv1_0!SpAcceptCredentials from LSASS.exe and DUMP DOMAIN/LOGIN/PASSWORD IN CLEARTEXT to text file.
☆121Jan 27, 2020Updated 6 years ago
Alternatives and similar repositories for LogonCredentialsSteal
Users that are interested in LogonCredentialsSteal are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Shellcode reflective DLL injection in Rust☆32May 3, 2026Updated 4 months ago
- Inject .Net payloads into other .Net assemblies on disk☆60Dec 12, 2019Updated 6 years ago
- A simple script to generate JScript code for calling Win32 API functions using XLM/Excel 4.0 macros via Excel.Application "ExecuteExcel4M…☆90Nov 9, 2019Updated 6 years ago
- ☆180Feb 3, 2021Updated 5 years ago
- PoC to demonstrate how CLR ETW events can be tampered.☆190Mar 26, 2020Updated 6 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A quick tool for hiding a new process running shellcode.☆57Jun 10, 2020Updated 6 years ago
- .Net Assembly to block ETW telemetry in current process☆78May 14, 2020Updated 6 years ago
- Run Rubeus via Rundll32☆214Apr 25, 2020Updated 6 years ago
- A Bind Shell Using the Fax Service and a DLL Hijack☆334May 3, 2020Updated 6 years ago
- .NET 4.0 WinRM API Command Execution☆164Sep 11, 2020Updated 6 years ago
- Alternative C# Implementation tool to retrieve Active Directory Integrated DNS records with IP addresses☆49Aug 8, 2020Updated 6 years ago
- Zipper, a CobaltStrike file and folder compression utility.☆221Jan 18, 2020Updated 6 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,667Jul 10, 2023Updated 3 years ago
- Capture screenshots from .NET using .NET methods or Windows API calls☆66Mar 9, 2020Updated 6 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Tool to create hidden registry keys.☆488Oct 23, 2019Updated 6 years ago
- Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.☆67Oct 3, 2020Updated 5 years ago
- Managed assembly shellcode generation☆280Mar 19, 2021Updated 5 years ago
- SharpClipHistory is a .NET application written in C# that can be used to read the contents of a user's clipboard history in Windows 10 st…☆200Jan 23, 2020Updated 6 years ago
- A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or pro…☆273May 3, 2023Updated 3 years ago
- .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py☆613Feb 16, 2023Updated 3 years ago
- RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.☆330Jul 7, 2023Updated 3 years ago
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆464Mar 8, 2023Updated 3 years ago
- CobaltStrike Aggressor Script to utilise FuzzySec's Windows Notification Framework Research to Spawn a Shell under Explorer.exe☆16Jul 6, 2019Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows PE - TLS (Thread Local Storage) Injector in C/C++☆106Jan 3, 2021Updated 5 years ago
- Create a minidump of the LSASS process from memory☆257Nov 2, 2022Updated 3 years ago
- Syscall BOF to arbitrarily add/detract process token privilege rights.☆68Jul 10, 2024Updated 2 years ago
- UAC Bypass By Abusing Kerberos Tickets☆512Aug 10, 2023Updated 3 years ago
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆343Jul 21, 2020Updated 6 years ago
- lateral movement techniques that can be used during red team exercises☆279Jan 13, 2020Updated 6 years ago
- Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load().☆215Mar 5, 2020Updated 6 years ago
- Allow a Go process to dynamically load .NET assemblies☆148Mar 28, 2020Updated 6 years ago
- Standalone version of my AES Powershell payload for Cobalt Strike.☆111Dec 27, 2019Updated 6 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Dump the memory of a PPL with a userland exploit☆889Jul 24, 2022Updated 4 years ago
- Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS head…☆597Jul 26, 2021Updated 5 years ago
- Use to browse the share file by eas(Exchange Server ActiveSync)☆46Jun 28, 2020Updated 6 years ago
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆252Sep 26, 2020Updated 6 years ago
- Various Cobalt Strike BOFs☆787Oct 16, 2022Updated 3 years ago
- Extracting Clear Text Passwords from mstsc.exe using API Hooking.☆1,468Jul 20, 2024Updated 2 years ago
- Collection of Beacon Object Files☆637Nov 1, 2022Updated 3 years ago