ustayready / tradecraftLinks
Red Teaming Tradecraft
☆14Updated 2 years ago
Alternatives and similar repositories for tradecraft
Users that are interested in tradecraft are comparing it to the libraries listed below
Sorting:
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated 4 months ago
- FrostLock Injection is a freeze/thaw-based code injection technique that uses Windows Job Objects to temporarily freeze (suspend) a targe…☆25Updated 2 months ago
- Windows AppLocker Driver (appid.sys) LPE☆62Updated 10 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- ☆34Updated 2 months ago
- Folder Or File Delete to Get System Shell on Current Session Desktop☆39Updated 5 months ago
- Repo containing my public talks☆23Updated 2 years ago
- ☆75Updated 10 months ago
- A more reliable way of resolving syscall numbers in Windows☆49Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 11 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated 10 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆57Updated 2 years ago
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Updated 3 years ago
- This is the combination of multiple evasion techniques to evade defenses. (Dirty Vanity)☆48Updated last year
- IDA Python scripts☆37Updated 2 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆116Updated 11 months ago
- Nim process hollowing loader☆57Updated 10 months ago
- ☆48Updated 3 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated 2 years ago
- Ghosting-AMSI☆17Updated last month
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆39Updated 7 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆31Updated 2 years ago
- ☆28Updated last year
- Bunch of BOF files☆32Updated 6 months ago
- .NET tool used to enrich RPC telemetry☆62Updated last week
- ☆48Updated 2 years ago
- ☆25Updated last week
- A pure C version of SymProcAddress☆27Updated last year