Project for identifying executables and DLLs vulnerable to environment-variable based DLL hijacking.
☆64Jul 15, 2022Updated 4 years ago
Alternatives and similar repositories for windows-dll-env-hijacking
Users that are interested in windows-dll-env-hijacking are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Project for tracking publicly disclosed DLL Hijacking opportunities.☆934Aug 21, 2026Updated last week
- Tool for pivoting over SMB pipes☆16Jul 20, 2019Updated 7 years ago
- CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process inject…☆241Jan 4, 2023Updated 3 years ago
- Ntdll Unhooking POC☆18Aug 12, 2022Updated 4 years ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆65Apr 4, 2026Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Files related to my presentation at SigSegV2 conference in 2019. You can find related papers on my blog☆12Dec 12, 2019Updated 6 years ago
- Process hollowing injection technique for Red Team operations☆19Sep 18, 2023Updated 2 years ago
- ☆15Nov 23, 2021Updated 4 years ago
- ☆51Sep 18, 2020Updated 5 years ago
- Various methods of executing shellcode☆75Mar 27, 2023Updated 3 years ago
- VisualStudio port of https://github.com/guervild/BOFs/tree/dev/SilentLsassDump☆23Jul 6, 2023Updated 3 years ago
- C++ self-Injecting dropper based on various EDR evasion techniques.☆446Feb 11, 2024Updated 2 years ago
- More examples using the Impacket library designed for learning purposes.☆265Nov 4, 2022Updated 3 years ago
- A C port of b33f's UrbanBishop☆38Oct 1, 2020Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆31Apr 1, 2022Updated 4 years ago
- Loading and executing shellcode in C# without PInvoke.☆22Jan 10, 2022Updated 4 years ago
- ☆24Jul 29, 2021Updated 5 years ago
- List web account manager (WAM) accounts added to the current profile☆26Dec 11, 2025Updated 8 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆92Sep 9, 2022Updated 3 years ago
- A mechanism that trampoline hooks functions in x86/x64 systems.☆21Oct 9, 2024Updated last year
- Simple tool to perform HTML Smuggling.☆66Aug 17, 2021Updated 5 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆94Oct 13, 2024Updated last year
- C# project to Reflectively load .Net assemblies in memory☆20Jun 19, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Reverse TCP Powershell has never been this paranoid. (basically an Opsec-safe reverse powershell)☆30Feb 4, 2022Updated 4 years ago
- ☆18Oct 30, 2022Updated 3 years ago
- A dotnet executable to get an Entra token in an authenticated runtime☆17Oct 30, 2024Updated last year
- DefCon Red Team Village 2023 Workshop on DLL Sideloading☆19Aug 15, 2023Updated 3 years ago
- Hide your P/Invoke signatures through other people's signed assemblies☆217Mar 10, 2024Updated 2 years ago
- ☆211Mar 22, 2021Updated 5 years ago
- ☆84Oct 18, 2022Updated 3 years ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆103Sep 18, 2023Updated 2 years ago
- Remotely enables Restricted Admin Mode☆214Sep 3, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆66Sep 15, 2022Updated 3 years ago
- XOrCryptEx lightweight C Utility/Algorithm☆13Mar 3, 2022Updated 4 years ago
- This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-…☆86Jul 2, 2019Updated 7 years ago
- EQGRP: Replicating DarkPulsar, an DLL capable of hooking Security Package Method Tables on the Heap!☆15Oct 11, 2020Updated 5 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆31Feb 11, 2021Updated 5 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆34Feb 7, 2022Updated 4 years ago
- A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.ht…☆678Dec 23, 2022Updated 3 years ago