termanix / TokenElevation
Token Elevation to authorized user as SYSTEM or Domain Admins
☆23Updated last year
Alternatives and similar repositories for TokenElevation:
Users that are interested in TokenElevation are comparing it to the libraries listed below
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- ☆58Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆78Updated 2 years ago
- Some of the presentations, workshops, and labs I gave at public conferences.☆29Updated 4 months ago
- A repository with my code snippets for research/education purposes.☆50Updated last year
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- A small Aggressor script to help Red Teams identify foreign processes on a host machine☆83Updated 2 years ago
- ☆47Updated last year
- Sniffing files generator☆49Updated 2 months ago
- ☆45Updated 2 months ago
- A care package of useful bofs for red team engagments☆53Updated last month
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆12Updated this week
- A pure C version of SymProcAddress☆24Updated 10 months ago
- Bypass AMSI By Dividing files into multiple smaller files☆45Updated 2 years ago
- Python module for running BOFs☆64Updated last year
- Python3 rewrite of AsOutsider features of AADInternals☆39Updated 3 weeks ago
- A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.☆36Updated 2 years ago
- Scripts for public use that we've randomly written, or have updated from other people's work.☆40Updated 6 months ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆70Updated last year
- ☆61Updated last week
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆45Updated 10 months ago
- Rewrite to fit my needs☆27Updated 5 months ago
- A BOF tool that can be used to collect passwords using CredUIPromptForWindowsCredentialsName.☆11Updated 2 years ago
- malleable profile generator GUI for Havoc☆56Updated last year
- ☆46Updated last year
- Click Once + App Domain☆62Updated last year
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- Small project to facilitate creation of .lnk payloads☆62Updated 2 years ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆20Updated 2 years ago