Project for identifying executables that have command-line options that can be obfuscated, possibly bypassing detection rules.
☆188Jan 27, 2025Updated last year
Alternatives and similar repositories for windows-command-line-obfuscation
Users that are interested in windows-command-line-obfuscation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆208Feb 24, 2022Updated 4 years ago
- PIC lsass dumper using cloned handles☆596Oct 18, 2022Updated 3 years ago
- BoobSnail allows generating Excel 4.0 XLM macro. Its purpose is to support the RedTeam and BlueTeam in XLM macro generation.☆256Mar 6, 2025Updated last year
- Load .net assemblies from memory while having them appear to be loaded from an on-disk location.☆173May 5, 2021Updated 5 years ago
- C# Reflective loader for unmanaged binaries.☆447Jan 25, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Managed code hooking template.☆134Nov 19, 2021Updated 4 years ago
- Load any Beacon Object File using Powershell!☆261Dec 9, 2021Updated 4 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆92Dec 15, 2022Updated 3 years ago
- SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.☆1,218Apr 16, 2025Updated last year
- Koppeling x Metatwin x LazySign☆218Aug 26, 2021Updated 4 years ago
- Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation☆997Oct 7, 2022Updated 3 years ago
- Shellcode injection POC using syscalls.☆116Jun 5, 2020Updated 6 years ago
- Self-developed tools for Lateral Movement/Code Execution☆724Aug 17, 2021Updated 4 years ago
- PowerShell Script Obfuscator☆604Nov 2, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Using "svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc" as trigger☆58Oct 7, 2020Updated 5 years ago
- SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature…☆1,286Aug 27, 2023Updated 2 years ago
- A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementin…☆536Aug 1, 2022Updated 3 years ago
- Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.☆287Jun 8, 2026Updated last month
- Read Excel Spreadsheets (XLS/XLSX) using Cobalt Strike's Execute-Assembly☆89Sep 30, 2024Updated last year
- ☆31Aug 23, 2020Updated 5 years ago
- Command line interface to dump LSASS memory to disk via SilentProcessExit☆457Dec 23, 2020Updated 5 years ago
- Some stuff for PHD2021☆14May 21, 2025Updated last year
- A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.☆297Aug 18, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in…☆271Mar 18, 2021Updated 5 years ago
- ☆435Aug 17, 2022Updated 3 years ago
- XLL Phishing Tradecraft☆441May 24, 2022Updated 4 years ago
- Porting of mimikatz sekurlsa::logonpasswords, sekurlsa::ekeys and lsadump::dcsync commands☆1,020Nov 7, 2021Updated 4 years ago
- Get file less command execution for lateral movement.☆639Jun 3, 2022Updated 4 years ago
- .NET Project for performing Authenticated Remote Execution☆410Feb 8, 2023Updated 3 years ago
- A User Impersonation tool - via Token or Shellcode injection☆422May 21, 2022Updated 4 years ago
- Scan files or process memory for CobaltStrike beacons and parse their configuration☆921Aug 19, 2021Updated 4 years ago
- Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies☆124May 29, 2024Updated 2 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- KaynLdr is a Reflective Loader written in C/ASM☆554Dec 3, 2023Updated 2 years ago
- A collection of my presentation materials.☆17Apr 29, 2024Updated 2 years ago
- C# tool for installing a shared network printer abusing the PrinterNightmare bug to allow other network machines easy privesc!☆181Aug 4, 2021Updated 4 years ago
- ☆134Jul 14, 2021Updated 5 years ago
- Deathstar is an Empire plugin that automates gaining Domain and/or Enterprise Admin rights in Active Directory environments using common …☆20Updated this week
- Lockless allows for the copying of locked files.☆256Apr 30, 2021Updated 5 years ago
- Remove API hooks from a Beacon process.☆284Sep 18, 2021Updated 4 years ago