scriptchildie / goEkkoLinks
Sleep obfuscation in golang based on ekko
☆13Updated last year
Alternatives and similar repositories for goEkko
Users that are interested in goEkko are comparing it to the libraries listed below
Sorting:
- A process injection technique using only thread context manipulation☆39Updated last year
- ☆124Updated last year
- Mockingjay process self injection POC☆41Updated 2 years ago
- Internal Monologue BOF☆77Updated 10 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆129Updated 2 months ago
- Simple BOF to read the protection level of a process☆119Updated 2 years ago
- AzureAD beacon object files☆129Updated 10 months ago
- Sliver extension performing TCP redirection tasks without performing cross-process injection.☆68Updated 9 months ago
- ForsHops☆149Updated 7 months ago
- Lateral movement with DCOM DLL hijacking☆166Updated 3 months ago
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆114Updated 3 months ago
- Lateral Movement Bof with MSI ODBC Driver Install☆132Updated last month
- Lateral Movement via the .NET Profiler☆84Updated 11 months ago
- ☆135Updated 8 months ago
- Local SYSTEM auth trigger for relaying - X☆147Updated 3 months ago
- ☆134Updated 9 months ago
- ☆114Updated 11 months ago
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆117Updated last year
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆104Updated 5 months ago
- Impersonate Tokens using only NTAPI functions☆80Updated 6 months ago
- Find DLLs with RWX section☆80Updated 2 years ago
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆68Updated last year
- A BOF to retrieve decryption keys for WhatsApp Desktop and a utility script to decrypt the databases.☆86Updated 7 months ago
- ☆120Updated 9 months ago
- ☆109Updated 8 months ago
- Spawns a process from a process. Can sometimes be used to run a session > 0 process from session 0.☆18Updated 3 years ago
- Linker for Beacon Object Files☆128Updated 2 weeks ago
- Run Cobalt Strike BOFs in Brute Ratel C4!☆79Updated 6 months ago
- A hoontr must hoont☆99Updated 2 months ago
- Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)☆59Updated last week