rkbennett / RunAsPyLinks
☆10Updated 3 months ago
Alternatives and similar repositories for RunAsPy
Users that are interested in RunAsPy are comparing it to the libraries listed below
Sorting:
- ☆98Updated 11 months ago
- ☆41Updated 2 months ago
- ☆47Updated 2 months ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆74Updated last year
- ☆53Updated 8 months ago
- In-memory sleep encryption and heap encryption for Go applications through a shellcode function.☆39Updated last year
- Beacon Object File (BOF) for identifying dependent child services of a given parent.☆17Updated 2 months ago
- Local SYSTEM auth trigger for relaying - X☆136Updated last month
- TokenCert☆100Updated 9 months ago
- ☆48Updated 3 months ago
- Adjusted version of the impacket-dcomexec script to work against Windows 10☆10Updated last year
- Bypassing Amsi using LdrLoadDll☆45Updated 7 months ago
- Lateral movement with DCOM DLL hijacking☆138Updated last month
- Copy metadata and digital signatures information from one Windows executable to another using Wine on a non-Windows platform☆18Updated last year
- A C# port from Invoke-GhostTask☆118Updated last year
- ☆53Updated 2 months ago
- Tool for working with Indirect System Calls in Cobalt Strike's Beacon Object Files (BOF) using SysWhispers3 for EDR evasion☆91Updated last month
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆54Updated 4 months ago
- Tool to bypass LSA Protection (aka Protected Process Light)☆56Updated 7 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆71Updated this week
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆102Updated 3 months ago
- ☆83Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆76Updated last year
- A simple tool to identify WDS servers in Active Directory☆29Updated this week
- Modified versions of the Cobalt Strike Process Injection Kit☆101Updated last year
- A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike☆149Updated last month
- Enumerate information from NTLM authentication enabled web endpoints 🔎☆34Updated 2 years ago
- Cobalt Strike UDRL for memory scanner evasion.☆51Updated last year
- ☆119Updated 7 months ago
- ☆31Updated last year