volexity / donut-decryptor
Retrieve inner payloads from Donut samples
☆82Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for donut-decryptor
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆113Updated 5 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆72Updated 2 months ago
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆106Updated 6 months ago
- Find DLLs with RWX section☆75Updated last year
- A Mythic Agent written in PIC C.☆92Updated this week
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 7 months ago
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆72Updated 9 months ago
- Local & remote Windows DLL Proxying☆160Updated 5 months ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆170Updated 8 months ago
- ☆68Updated last year
- Living Off the Foreign Land setup scripts☆63Updated 3 weeks ago
- ☆72Updated 7 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆95Updated 7 months ago
- Async Python library to parse local and remote disk images.☆75Updated 2 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆83Updated 5 months ago
- Rusty Impersonate☆94Updated last year
- ☆104Updated this week
- ☆73Updated last year
- ☆83Updated 2 years ago
- Find .net assemblies locally☆92Updated 2 years ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆88Updated last year
- ☆44Updated 3 weeks ago
- ☆83Updated 6 months ago
- Python module for running BOFs☆64Updated last year
- ☆109Updated 3 years ago
- ☆98Updated 3 weeks ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆110Updated last year
- Simple BOF to read the protection level of a process☆104Updated last year
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆89Updated last year
- Your syscall factory☆121Updated 2 months ago