som3canadian / Mythic_NimSyscallPacker_Wrapper
Mythic C2 wrapper for NimSyscallPacker
☆23Updated 3 months ago
Alternatives and similar repositories for Mythic_NimSyscallPacker_Wrapper:
Users that are interested in Mythic_NimSyscallPacker_Wrapper are comparing it to the libraries listed below
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 9 months ago
- .NET port of Leron Gray's azbelt tool.☆26Updated last year
- Scripts to interact with Microsoft Graph APIs☆33Updated 3 months ago
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆36Updated 4 months ago
- ☆17Updated 2 months ago
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 9 months ago
- Extension functionality for the NightHawk operator client☆26Updated last year
- A simple rpc2socks alternative in pure Go.☆28Updated 7 months ago
- Quick and dirty PowerShell script to abuse the overly permissive capabilities of the SYSTEM user in a child domain on the Public Key Serv…☆25Updated last year
- A C# port of https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80☆19Updated last year
- Create PDFs with HTML smuggling attachments that save on opening the document.☆29Updated last year
- Nemesis agent for Mythic☆26Updated 6 months ago
- Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.☆12Updated 9 months ago
- Unix Process hollowing in rust☆20Updated 2 months ago
- Items related to the RedELK workshop given at security conferences☆28Updated last year
- A simple to use single-include Windows API resolver☆20Updated 7 months ago
- ☆47Updated 2 years ago
- Watches the Downloads folder for any new files and inserts it into Nemesis for analysis.☆14Updated last year
- Python3 rewrite of AsOutsider features of AADInternals☆40Updated 2 months ago
- Reverse-HTTP Redirector via DigitalOcean Apps Platform☆28Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 7 months ago
- A vSphere deployment of GOADv2 BETA Testing (v0.1)☆26Updated last year
- Docker container for running CobaltStrike 4.10☆36Updated 5 months ago
- Identify binaries with Authenticode digital signatures signed to an internal CA/domain☆37Updated last year
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- A pure C version of SymProcAddress☆25Updated 11 months ago