susMdT / AceLdrLinks
Cobalt Strike UDRL for memory scanner evasion.
☆52Updated 2 years ago
Alternatives and similar repositories for AceLdr
Users that are interested in AceLdr are comparing it to the libraries listed below
Sorting:
- Click Once + App Domain☆64Updated 2 years ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Updated 9 months ago
- DLL proxy load example using the Windows thread pool API, I/O completion callback with named pipes, and C++/assembly☆63Updated last year
- ☆50Updated 8 months ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆42Updated 2 years ago
- Beacon Object File (BOF) for Using the BadSuccessor Technique for Account Takeover☆85Updated 3 months ago
- An Aggressor Script that utilizes NtCreateUserProcess to run binaries☆30Updated last year
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆88Updated last month
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆45Updated last year
- ☆53Updated 4 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆42Updated 10 months ago
- ☆51Updated 7 months ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75Updated last year
- Rewrite to fit my needs☆32Updated last year
- Beacon Object Files (not Buffer Overflows)☆58Updated 2 years ago
- A way to maintain long-term access to Windows LAPS for lateral movement in AD via installing an Offensive LAPS RPC backdoor on a DC.☆29Updated 8 months ago
- Copy metadata and digital signatures information from one Windows executable to another using Wine on a non-Windows platform☆19Updated last year
- Using LNK files and user input simulation to start processes under explorer.exe☆33Updated last year
- ☆35Updated last year
- A VSCode plugin to assist with BOF development.☆37Updated last year
- converts sRDI compatible dlls to shellcode☆35Updated last year
- Bypassing Amsi using LdrLoadDll☆47Updated last year
- ☆100Updated last year
- Cobalt Strike Beacon Object File (BOF) that uses CredUIPromptForWindowsCredentials API to invoke credential prompt☆23Updated 3 years ago
- A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.☆128Updated 2 weeks ago
- Porting of NPPSPY by Grzegorz Tworek to 'man in the middle' the user logon process, and store the user's name and password in an unassumi…☆19Updated 2 years ago
- Threadless shellcode injection tool☆68Updated last year
- ☆75Updated 2 years ago
- A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation☆18Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆63Updated 7 months ago