Project for identifying executables and DLLs vulnerable to environment-variable based DLL hijacking.
☆63Jul 15, 2022Updated 4 years ago
Alternatives and similar repositories for windows-dll-env-hijacking
Users that are interested in windows-dll-env-hijacking are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Project for tracking publicly disclosed DLL Hijacking opportunities.☆936Sep 9, 2026Updated last week
- Tool for pivoting over SMB pipes☆16Jul 20, 2019Updated 7 years ago
- CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process inject…☆241Jan 4, 2023Updated 3 years ago
- Ntdll Unhooking POC☆18Aug 12, 2022Updated 4 years ago
- DLL Unlinking from InLoadOrderModuleList, InMemoryOrderModuleList, InInitializationOrderModuleList, and LdrpHashTable☆65Apr 4, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Files related to my presentation at SigSegV2 conference in 2019. You can find related papers on my blog☆12Dec 12, 2019Updated 6 years ago
- Process hollowing injection technique for Red Team operations☆18Sep 18, 2023Updated 3 years ago
- ☆15Nov 23, 2021Updated 4 years ago
- ☆51Sep 18, 2020Updated 6 years ago
- Various methods of executing shellcode☆75Mar 27, 2023Updated 3 years ago
- VisualStudio port of https://github.com/guervild/BOFs/tree/dev/SilentLsassDump☆22Jul 6, 2023Updated 3 years ago
- C++ self-Injecting dropper based on various EDR evasion techniques.☆444Feb 11, 2024Updated 2 years ago
- More examples using the Impacket library designed for learning purposes.☆264Nov 4, 2022Updated 3 years ago
- A C port of b33f's UrbanBishop☆38Oct 1, 2020Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆31Apr 1, 2022Updated 4 years ago
- Loading and executing shellcode in C# without PInvoke.☆22Jan 10, 2022Updated 4 years ago
- ☆24Jul 29, 2021Updated 5 years ago
- List web account manager (WAM) accounts added to the current profile☆26Dec 11, 2025Updated 9 months ago
- Deleting Shadow Copies In Pure C++☆118Oct 31, 2022Updated 3 years ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆91Sep 9, 2022Updated 4 years ago
- A mechanism that trampoline hooks functions in x86/x64 systems.☆21Oct 9, 2024Updated last year
- Simple tool to perform HTML Smuggling.☆65Aug 17, 2021Updated 5 years ago
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆94Oct 13, 2024Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Reverse TCP Powershell has never been this paranoid. (basically an Opsec-safe reverse powershell)☆30Feb 4, 2022Updated 4 years ago
- C# project to Reflectively load .Net assemblies in memory☆20Jun 19, 2024Updated 2 years ago
- ☆18Oct 30, 2022Updated 3 years ago
- A dotnet executable to get an Entra token in an authenticated runtime☆17Oct 30, 2024Updated last year
- DefCon Red Team Village 2023 Workshop on DLL Sideloading☆19Aug 15, 2023Updated 3 years ago
- Hide your P/Invoke signatures through other people's signed assemblies☆216Mar 10, 2024Updated 2 years ago
- ☆84Oct 18, 2022Updated 3 years ago
- ☆210Mar 22, 2021Updated 5 years ago
- DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.☆103Sep 18, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CLIPBRDWNDCLASS process injection technique(BOF) - execute beacon shellcode in callback☆65Sep 15, 2022Updated 4 years ago
- Remotely enables Restricted Admin Mode☆214Sep 3, 2021Updated 5 years ago
- XOrCryptEx lightweight C Utility/Algorithm☆13Mar 3, 2022Updated 4 years ago
- This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-…☆86Jul 2, 2019Updated 7 years ago
- EQGRP: Replicating DarkPulsar, an DLL capable of hooking Security Package Method Tables on the Heap!☆15Oct 11, 2020Updated 5 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆31Feb 11, 2021Updated 5 years ago
- Tiny driver patch to allow kernel callbacks to work on Win10 21h1☆33Feb 7, 2022Updated 4 years ago