volexity / donut-decryptor
Retrieve inner payloads from Donut samples
☆90Updated last year
Alternatives and similar repositories for donut-decryptor:
Users that are interested in donut-decryptor are comparing it to the libraries listed below
- Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning☆127Updated 2 months ago
- Local & remote Windows DLL Proxying☆162Updated 8 months ago
- ☆112Updated last year
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 6 months ago
- ☆85Updated 9 months ago
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆144Updated 9 months ago
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆83Updated 10 months ago
- A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).☆93Updated 2 years ago
- ☆107Updated 3 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆172Updated 2 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆188Updated last month
- IoctlHunter is a command-line tool designed to simplify the analysis of IOCTL calls made by userland software targeting Windows drivers.☆95Updated last year
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆115Updated 8 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 5 months ago
- Find .net assemblies locally☆104Updated 2 years ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- A BOF to enumerate system process, their protection levels, and more.☆113Updated 2 months ago
- Example code samples from our ScriptBlock Smuggling Blog post☆88Updated 8 months ago
- Port of Cobalt Strike's Process Inject Kit☆165Updated 2 months ago
- ☆75Updated last year
- ☆143Updated 2 months ago
- IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then refle…☆109Updated 9 months ago
- ☆180Updated last year
- Identifies bad bytes from static analysis with any Anti-Virus scanner.☆122Updated 7 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 10 months ago
- ☆103Updated 3 months ago
- Find DLLs with RWX section☆76Updated last year
- ☆165Updated last year
- Recursive Loader☆101Updated 4 months ago
- ☆139Updated 6 months ago