raykaryshyn / FakeTLS
Client/server code that impersonates TLS 1.3 to disguise C2 activity.
☆68Updated 2 years ago
Alternatives and similar repositories for FakeTLS
Users that are interested in FakeTLS are comparing it to the libraries listed below
Sorting:
- An implementation of an indirect system call☆126Updated last year
- ☆96Updated 3 years ago
- bring your own vulnerable driver☆95Updated 2 years ago
- It stinks☆102Updated 3 years ago
- A basic C2 framework written in C☆61Updated 10 months ago
- Simple windows rpc server for research purposes only☆82Updated 2 years ago
- Windows API Call Obfuscation☆103Updated 2 years ago
- ☆165Updated 3 years ago
- ☆115Updated 2 years ago
- Windows Defender VDM lua collections☆47Updated 2 years ago
- Load static-compiled PE from remote server.☆61Updated 3 years ago
- DLL Hollowing PoC - Remote and Self shellcode injection☆79Updated 3 years ago
- Bypass UAC by abusing the Internet Explorer Add-on installer☆54Updated 3 years ago
- Beacon compiled using clang☆67Updated 2 years ago
- Cobalt Strike User Defined Reflective Loader (UDRL). Check branches for different functionality.☆144Updated 2 years ago
- ☆49Updated 2 years ago
- Exploring in-memory execution of .NET☆137Updated 3 years ago
- A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process☆100Updated 2 years ago
- ☆140Updated 2 years ago
- shellcode-loaders and beacon-loaders☆64Updated last year
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆60Updated 4 years ago
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆63Updated 2 years ago
- The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/☆185Updated 2 years ago
- Amaterasu terminates, or inhibits, protected processes such as application control and AV/EDR solutions by leveraging the Sysinternals Pr…☆72Updated last year
- XOR decrypting shellcode using the GPU with OpenCL.☆98Updated 2 years ago
- ☆239Updated last year
- PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)☆106Updated 3 years ago
- Load and execute COFF files and Cobalt Strike BOFs in-memory☆216Updated 2 years ago
- Minimal PoC developed as discuss in https://captmeelo.com/redteam/maldev/2022/05/10/ntcreateuserprocess.html☆137Updated 3 years ago
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆69Updated 2 years ago