winscripting / UAC-bypassLinks
☆233Updated 8 years ago
Alternatives and similar repositories for UAC-bypass
Users that are interested in UAC-bypass are comparing it to the libraries listed below
Sorting:
- Generates malicious LNK file payloads for data exfiltration☆426Updated 8 years ago
- A meterpreter extension for applying hooks to avoid windows defender memory scans☆249Updated 5 years ago
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆347Updated 5 years ago
- Tool to create hidden registry keys.☆489Updated 6 years ago
- ☆364Updated 4 years ago
- ☆481Updated 2 years ago
- The project is designed as a file resource cloner. Metadata, including digital signature, is extracted from one file and injected into a…☆358Updated last year
- This repo will contain code snippets for blogs: Malware on Steroids written by me at https://scriptdotsh.com/index.php/category/malware-d…☆199Updated 5 years ago
- 2018 School project - PoC of malware code obfuscation in Word macros☆153Updated 4 years ago
- Example DLL to load from Windows NetShell☆183Updated 9 years ago
- A Bind Shell Using the Fax Service and a DLL Hijack☆330Updated 5 years ago
- Malicious Shortcut(.lnk) Generator☆198Updated 7 years ago
- ** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + …☆218Updated 2 years ago
- Windows - Weaponizing privileged file writes with the Update Session Orchestrator service☆399Updated 5 years ago
- Manipulating and Abusing Windows Access Tokens.☆289Updated 4 years ago
- RACE is a PowerShell module for executing ACL attacks against Windows targets.☆235Updated 2 years ago
- DLL and PowerShell script to assist with finding DLL hijacks☆340Updated 5 years ago
- Bypass for PowerShell Constrained Language Mode☆402Updated 3 years ago
- Tools for discovery and abuse of COM hijacks☆330Updated 6 years ago
- Steal a primary token and spawn cmd.exe using the stolen token☆258Updated 4 years ago
- C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.☆426Updated last year
- A VBA implementation of the RunPE technique or how to bypass application whitelisting.☆816Updated 5 years ago
- ☆500Updated 8 years ago
- Bypass AMSI by patching AmsiScanBuffer☆275Updated 4 years ago
- ☆263Updated 2 years ago
- ☆257Updated 7 years ago
- OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at s…☆537Updated 3 years ago
- Dll that can be used for side loading and other attack vector.☆203Updated 5 years ago
- Process Injection☆765Updated 4 years ago
- A modular C2 framework☆493Updated last week