UAC Bypass via CMUACUtil & PEB Enumeration, Undetected for now.
☆52May 8, 2024Updated 2 years ago
Alternatives and similar repositories for UAC-Bypass
Users that are interested in UAC-Bypass are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆189Jun 14, 2025Updated last year
- Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)☆264Jun 29, 2024Updated 2 years ago
- A Simple PoC☆22May 24, 2024Updated 2 years ago
- ☆246May 5, 2024Updated 2 years ago
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆249Jun 11, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆140May 22, 2024Updated 2 years ago
- ☆346Jun 24, 2026Updated 3 months ago
- ☆106Sep 5, 2023Updated 3 years ago
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆105Mar 25, 2025Updated last year
- SOCKS, HTTP and Reverse Proxy server based on .NET☆16Oct 28, 2024Updated last year
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆302Sep 18, 2024Updated 2 years ago
- A collection of (even more) alternative shellcode callback methods in CSharp☆81Oct 26, 2024Updated last year
- A POC to disable TamperProtection and other Defender / MDE components☆259Jun 6, 2024Updated 2 years ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆66Mar 19, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- .NET assembly loader with patchless AMSI and ETW bypass☆391Apr 19, 2023Updated 3 years ago
- A .NET 4.8 application to retrieve delivr.to emails from Microsoft Outlook via COM☆20Jul 19, 2025Updated last year
- XOR decrypting shellcode using the GPU with OpenCL. Original PoC adopted by e.g. CoffeeLoader, GpuGate.☆130May 22, 2025Updated last year
- Lateral Movement via the .NET Profiler☆100Nov 21, 2024Updated last year
- A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and …☆335Mar 6, 2025Updated last year
- Load a dynamic library from memory by modifying the native Windows loader☆307May 5, 2026Updated 5 months ago
- List the ETW provider(s) in the registration table of a process.☆79Sep 20, 2023Updated 3 years ago
- ☆62May 31, 2024Updated 2 years ago
- Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute☆25Jun 5, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- .NET/PowerShell/VBA Offensive Security Obfuscator☆219May 4, 2024Updated 2 years ago
- ☆151Oct 2, 2023Updated 3 years ago
- PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.☆628Sep 26, 2023Updated 3 years ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆86Mar 19, 2023Updated 3 years ago
- Improved version of EKKO by @5pider that Encrypts only Image Sections☆122Feb 13, 2023Updated 3 years ago
- Local SYSTEM auth trigger for relaying☆173Jul 22, 2025Updated last year
- ☆179Mar 27, 2023Updated 3 years ago
- Bypass Credential Guard by patching WDigest.dll using only NTAPI functions☆269Apr 8, 2025Updated last year
- ☆17Nov 23, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆110Aug 21, 2024Updated 2 years ago
- NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs☆97Apr 4, 2026Updated 6 months ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆125May 29, 2024Updated 2 years ago
- Shellcode Loader Utilizing ETW Events☆65Feb 26, 2025Updated last year
- Remotely Enumerate sessions using undocumented Windows Station APIs☆116Aug 21, 2024Updated 2 years ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆395Dec 13, 2024Updated last year
- Use hardware breakpoints to spoof the call stack for both syscalls and API calls☆204Jun 6, 2024Updated 2 years ago