slyd0g / DLLHijackTest
DLL and PowerShell script to assist with finding DLL hijacks
☆329Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for DLLHijackTest
- Command line interface to dump LSASS memory to disk via SilentProcessExit☆442Updated 3 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆679Updated 2 months ago
- The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.☆466Updated 2 years ago
- PIC lsass dumper using cloned handles☆573Updated 2 years ago
- A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from …☆875Updated 3 years ago
- Various Cobalt Strike BOFs☆581Updated 2 years ago
- Cobalt Strike kit for Lateral Movement☆647Updated 4 years ago
- Executes position independent shellcode from an encrypted zip☆300Updated 3 years ago
- ☆349Updated 3 years ago
- Collection of Beacon Object Files☆552Updated 2 years ago
- Project for identifying executables and DLLs vulnerable to relative path DLL hijacking.☆441Updated 6 months ago
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆341Updated 4 years ago
- Cobalt Strike kit for Persistence☆465Updated 4 years ago
- Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)☆308Updated 3 years ago
- StandIn is a small .NET35/45 AD post-exploitation toolkit☆703Updated 11 months ago
- Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks b…☆429Updated last year
- A .NET Framework 4.0 Windows Agent☆454Updated last week
- A meterpreter extension for applying hooks to avoid windows defender memory scans☆240Updated 4 years ago
- Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)☆409Updated 3 years ago
- Convert Cobalt Strike profiles to modrewrite scripts☆583Updated last year
- Dump the memory of a PPL with a userland exploit☆845Updated 2 years ago
- .NET Project for performing Authenticated Remote Execution☆379Updated last year
- ☆347Updated 2 years ago
- Steal a primary token and spawn cmd.exe using the stolen token☆252Updated 3 years ago
- This is a PowerShell Empire launcher PoC using PrintDemon and Faxhell.☆198Updated 4 years ago
- Self-developed tools for Lateral Movement/Code Execution☆692Updated 3 years ago
- Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely☆397Updated 2 years ago