winsecurity / AMSI-Bypass-HWBPLinks
☆26Updated 6 months ago
Alternatives and similar repositories for AMSI-Bypass-HWBP
Users that are interested in AMSI-Bypass-HWBP are comparing it to the libraries listed below
Sorting:
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆80Updated 2 weeks ago
- This repo contains useful scripts that AI created for me which I would have been too lazy for☆76Updated this week
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆38Updated 2 months ago
- BOF for C2 framework☆44Updated last year
- Enable or Disable TokenPrivilege(s)☆15Updated last year
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆74Updated 2 weeks ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated last year
- ☆59Updated last year
- RPC to WebClient startup☆54Updated 5 months ago
- A simple C++ Windows tool to get information about processes exposing named pipes.☆40Updated 11 months ago
- ☆41Updated 11 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆36Updated 2 months ago
- in-process powershell runner for BRC4☆48Updated 2 years ago
- Impersonate Tokens using only NTAPI functions☆83Updated 10 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆140Updated 2 months ago
- use python on windows with full submodule support without installation☆30Updated last year
- ☆36Updated 7 months ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆66Updated last year
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆78Updated last year
- A portable C# utility for enumerating local and remote windows sessions☆55Updated last month
- Bypasses AMSI protection through remote memory patching and parsing technique.☆54Updated 9 months ago
- an Improoved Version of 0xNinjaCyclone´s EarlyCascade Code☆22Updated 11 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆74Updated 5 months ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆78Updated 5 months ago
- A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow☆18Updated 7 months ago
- Easy peasy file uploads☆33Updated 5 months ago
- Cortex EDR Ransomware protection Bypass☆25Updated last year
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆46Updated last year
- A Python script for creating `.lnk` (shortcut) files with embedded encoded data and packaging them into ZIP archives.☆92Updated last year
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆57Updated 9 months ago