usdAG / SharpLink
Create file system symbolic links from low privileged user accounts within PowerShell
☆90Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for SharpLink
- ☆37Updated 2 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆134Updated 5 months ago
- Find .net assemblies locally☆88Updated 2 years ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆110Updated last year
- ☆83Updated 2 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆130Updated last month
- A fake AMSI Provider which can be used for persistence.☆139Updated 3 years ago
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆119Updated 3 years ago
- Find DLLs with RWX section☆75Updated last year
- Unchain AMSI by patching the provider’s unmonitored memory space☆87Updated last year
- Dynamically invoke arbitrary unmanaged code from managed code without P/Invoke.☆145Updated 9 months ago
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆110Updated last year
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆114Updated 5 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- D/Invoke implementation in Nim☆98Updated 2 years ago
- Parse SDDL strings☆35Updated 7 months ago
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆79Updated 6 months ago
- C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.☆101Updated last year
- ☆83Updated 3 years ago
- ☆139Updated last year
- An example of using Syscalls in C# to get a meterpreter shell.☆107Updated 3 years ago
- A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading☆83Updated last year
- Tool for playing with Windows Access Token manipulation.☆51Updated last year
- Async Python library to parse local and remote disk images.☆75Updated 2 months ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆87Updated 2 years ago
- Implant drop-in for EDR testing☆127Updated 11 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆85Updated 2 years ago