Remap ntdll.dll using only NTAPI functions with a suspended process
☆28Apr 13, 2025Updated last year
Alternatives and similar repositories for NativeNtdllRemap
Users that are interested in NativeNtdllRemap are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Impersonate Tokens using only NTAPI functions☆85Apr 4, 2025Updated last year
- Safely manage the unloading of DLLs that have been hooked into a process. Context: https://github.com/KNSoft/KNSoft.SlimDetours/discussio…☆82Jun 21, 2025Updated 11 months ago
- Listener that spawns a new tmux window for each incoming reverse shell + Supports listening on many ports☆61Jul 13, 2025Updated 10 months ago
- Repository to gather the BOF files I will be developing☆11Oct 1, 2024Updated last year
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆86Jan 26, 2026Updated 4 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A tool to analyze Ntds.dit files once the NTLM and LM hashes have been cracked.☆15May 13, 2021Updated 5 years ago
- tool for enumeration & bulk download of sensitive files found in SharePoint environments☆85Apr 2, 2025Updated last year
- Repository to gather the .NET malware I will be developing☆18Mar 7, 2026Updated 2 months ago
- The ultimate Red Team toolkit for phishing operations.☆72May 15, 2026Updated last week
- Groovy Post Exploitation☆20Oct 21, 2024Updated last year
- Script to extract the cached credentials from SSSD, getting Active Directory credentials from Unix systems☆24Jun 14, 2023Updated 2 years ago
- Cobalt Strike BOF for evasive .NET assembly execution☆319Mar 31, 2025Updated last year
- ☆19Sep 17, 2025Updated 8 months ago
- Some simple code to learn about how to access the Windows network stack using polling and \Device\Afd☆31Jun 20, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Scripts that automate portions of pentests.☆58May 15, 2026Updated last week
- PoC to self-delete a binary in C#☆36Feb 6, 2024Updated 2 years ago
- EMQX Dashboard Malicious Plugin leading to RCE☆47Jun 16, 2025Updated 11 months ago
- The SecurityTube Linux Assembly Expert (SLAE) is an online course and certification which focuses on teaching the basics of 32-bit assemb…☆22Mar 31, 2019Updated 7 years ago
- Tool for working with Indirect System Calls in Cobalt Strike's Beacon Object Files (BOF) using SysWhispers3 for EDR evasion☆104Jul 9, 2025Updated 10 months ago
- Periodically check hashcat cracking progress and notify of success.☆10Dec 18, 2018Updated 7 years ago
- SafeCrypt is an academic ransomware simulation suite developed for Red Team engagements. It demonstrates modern malware techniques includ…☆34Oct 3, 2025Updated 7 months ago
- Downloading Spotify Playlists☆28May 20, 2026Updated last week
- P/Invoke definitions from the most-of-the-time offline offline pinvoke.net. Website: https://ricardojoserf.gitbook.io/pinvoke☆23Mar 23, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Proof of Concepts code for Bring Your Own Vulnerable Driver techniques☆109Aug 21, 2025Updated 9 months ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆34Nov 13, 2023Updated 2 years ago
- C# loader capable of running stage-1 from remote url, file path as well as file share☆14Feb 8, 2023Updated 3 years ago
- Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)☆24Oct 23, 2021Updated 4 years ago
- Self-cleaning in-memory PICO loader for Crystal Palace. Automatically erases traces and operates entirely in memory for stealthy payload …☆53Nov 2, 2025Updated 6 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆129Dec 23, 2025Updated 5 months ago
- kernel-mode DLL Injector☆139Apr 25, 2026Updated last month
- Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust☆84Mar 7, 2026Updated 2 months ago
- BypassCredGuard CS BOF☆54Jan 23, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Obfuscate payloads using IPv4, IPv6, MAC or UUID strings☆24Feb 17, 2024Updated 2 years ago
- All Apprentice and Practitioner-level Portswigger labs☆37May 18, 2023Updated 3 years ago
- Impersonate Windows tokens in Nim☆23Aug 4, 2025Updated 9 months ago
- ☆84May 19, 2024Updated 2 years ago
- ☆15Aug 22, 2022Updated 3 years ago
- Chrome browser extension-based Command & Control☆259Mar 18, 2026Updated 2 months ago
- A Powershell AMSI Bypass technique via Vectored Exception Handler (VEH). This technique does not perform assembly instruction patching, f…☆174May 30, 2024Updated last year