ricardojoserf / SharpNado
Repository to gather the .NET malware I will be developing
☆11Updated last month
Alternatives and similar repositories for SharpNado:
Users that are interested in SharpNado are comparing it to the libraries listed below
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆72Updated 4 years ago
- PoC to self-delete a binary in C#☆29Updated 11 months ago
- ☆87Updated 2 weeks ago
- UAC Bypass via CMUACUtil & PEB Enumeration, Undetected for now.☆45Updated 8 months ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆104Updated last year
- ☆113Updated last year
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆173Updated 10 months ago
- early cascade injection PoC based on Outflanks blog post, in rust☆50Updated 2 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆172Updated last year
- ☆120Updated last year
- Windows NTLM hash dump utility written in C language, that supports Windows and Linux. Hashes can be dumped in realtime or from already s…☆56Updated last year
- Simple C# Redirector☆80Updated last month
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- ☆122Updated 4 months ago
- Tool for playing with Windows Access Token manipulation.☆53Updated 2 years ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆73Updated 5 months ago
- ☆37Updated 2 years ago
- Malware?☆69Updated 3 months ago
- Encode shellcode into dictionary words for evasion and entropy reduction☆23Updated 2 months ago
- A collection of (even more) alternative shellcode callback methods in CSharp☆69Updated 3 months ago
- ☆127Updated last year
- Shellcode loader using direct syscalls via Hell's Gate and payload encryption.☆84Updated 7 months ago
- A C# implementation of dumping credentials from Windows Credential Manager☆56Updated last year
- BOF with Synthetic Stackframe☆103Updated this week
- Lateral Movement via the .NET Profiler☆77Updated 2 months ago
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆72Updated 10 months ago
- Dynamically invoke arbitrary unmanaged code from managed code without P/Invoke.☆149Updated last year
- Patch AMSI and ETW in remote process via direct syscall☆80Updated 2 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆139Updated 8 months ago