winsecurity / AMSI-Bypass-HWBPLinks
☆26Updated 5 months ago
Alternatives and similar repositories for AMSI-Bypass-HWBP
Users that are interested in AMSI-Bypass-HWBP are comparing it to the libraries listed below
Sorting:
- Create, delete or list Shadows Copies using the VSS API using C++, C# or Python. Working on Windows 11☆46Updated last week
- ☆59Updated last year
- ☆41Updated 11 months ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆38Updated last month
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- ☆32Updated last year
- RPC to WebClient startup☆53Updated 5 months ago
- BOF for C2 framework☆44Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆46Updated last year
- use python on windows with full submodule support without installation☆30Updated 11 months ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆66Updated 11 months ago
- A simple C++ Windows tool to get information about processes exposing named pipes.☆40Updated 10 months ago
- Impersonate Tokens using only NTAPI functions☆83Updated 9 months ago
- Permanently disable EDRs as local admin☆124Updated last month
- Sniffing files generator☆59Updated 10 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆78Updated 4 months ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Updated 9 months ago
- Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability☆24Updated 11 months ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated 11 months ago
- Tool to obtain hash using MS-SNTP for user accounts☆28Updated 11 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆139Updated last month
- A portable C# utility for enumerating local and remote windows sessions☆54Updated 2 weeks ago
- ☆55Updated 7 months ago
- Automatically extract and decrypt all configured scanning credentials of a Lansweeper instance.☆45Updated last year
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆72Updated 4 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆36Updated last month
- ☆36Updated 6 months ago
- Enable or Disable TokenPrivilege(s)☆15Updated last year
- CVE-2025-59501 POC code☆25Updated 2 months ago
- in-process powershell runner for BRC4☆48Updated 2 years ago