rmdavy / AMSI_Ordinal_BypassLinks
Bypass AMSI and Defender using Ordinal Values
☆42Updated 5 years ago
Alternatives and similar repositories for AMSI_Ordinal_Bypass
Users that are interested in AMSI_Ordinal_Bypass are comparing it to the libraries listed below
Sorting:
- External C2 Using IE COM Objects☆102Updated 6 years ago
- Port of Invoke-Excel4DCOM☆104Updated 6 years ago
- Credential Dumper☆77Updated 5 years ago
- Aggressor Script to Execute Assemblies from Github☆71Updated 5 years ago
- .Net Assembly to block ETW telemetry in current process☆81Updated 5 years ago
- Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.☆67Updated 5 years ago
- ☆73Updated 4 years ago
- A repo to hold any bypasses I work on/study/whatever☆19Updated 4 years ago
- Suite of Shellcode Running Utilities☆114Updated 5 years ago
- Initial Commit of Coresploit☆57Updated 4 years ago
- Cobalt Strike cna script for randomized argument spoofing☆51Updated 6 years ago
- My musings with C#☆28Updated 2 years ago
- Send message on Telegram when you get a new Cobalt Strike beacon☆21Updated 6 years ago
- ☆54Updated 6 years ago
- Outlook persistence using VSTO add-ins☆87Updated 4 years ago
- .NET 4.0 Scheduled Job Lateral Movement☆90Updated 5 years ago
- C# .NET Assembly for interacting with File Object DACLs☆44Updated 5 years ago
- Standalone version of my AES Powershell payload for Cobalt Strike.☆111Updated 5 years ago
- ☆48Updated 5 years ago
- Microsoft Applocker evasion tool☆39Updated 6 years ago
- Helper script for mangling CS payloads☆51Updated 6 years ago
- C2Bridges allow developers to create new custom communication protocols and quickly utilize them within Covenant.☆69Updated 4 years ago
- PowerView menu for Cobalt Strike☆69Updated 7 years ago
- ☆37Updated 6 years ago
- A script that can be deployed to Azure App for C2 / Proxy / Redirector☆41Updated 6 years ago
- C# Shellcode Runner to execute shellcode via CreateRemoteThread and SetThreadContext to evade Get-InjectedThread☆118Updated 6 years ago
- I used this to see if an EDR is running in Safe Mode☆36Updated 4 years ago
- adding a backdooruser using win32api☆80Updated 5 years ago
- ☆35Updated 8 years ago
- Smart overlay for Cobalt Strike PS function☆31Updated 6 years ago