A collection of (even more) alternative shellcode callback methods in CSharp
☆81Oct 26, 2024Updated last year
Alternatives and similar repositories for CSharp-Alt-Shellcode-Callbacks
Users that are interested in CSharp-Alt-Shellcode-Callbacks are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A C# Solution Source Obfuscator for avoiding AV signatures with minimal user interaction. Powered by the Roslyn C# library.☆105Mar 25, 2025Updated last year
- Click Once + App Domain☆69Feb 23, 2026Updated 5 months ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆133Jan 14, 2023Updated 3 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆100Feb 28, 2023Updated 3 years ago
- Custom Python shellcode encryptor and obfuscator☆15Jul 31, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- COFF file (BOF) for managing Kerberos tickets.☆328Jul 2, 2023Updated 3 years ago
- Lockless BOF☆79May 2, 2025Updated last year
- Utilizing hardware breakpoints to evade monitoring by Endpoint Detection and Response platforms☆139Dec 20, 2022Updated 3 years ago
- Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak☆210Nov 12, 2025Updated 8 months ago
- Beacon Object File implementation of Event Viewer deserialization UAC bypass☆133May 6, 2022Updated 4 years ago
- EmbedExeLnk by x86matthew modified by d4rkiZ☆46Apr 27, 2023Updated 3 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆93Dec 15, 2022Updated 3 years ago
- List/Read contents of Zip files (in memory and without extraction) using CobaltStrike's Execute-Assembly☆61May 24, 2022Updated 4 years ago
- Ansible Cobalt Strike (Docker)☆15Jan 8, 2022Updated 4 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆57Apr 19, 2023Updated 3 years ago
- Encode shellcode into dictionary words for evasion and entropy reduction☆43Dec 12, 2025Updated 7 months ago
- ☆39Oct 12, 2022Updated 3 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆67Aug 23, 2023Updated 2 years ago
- ☆124Dec 23, 2022Updated 3 years ago
- Cobalt Strike Beacon Object File (BOF) that uses RegConnectRegistryA + RegOpenKeyExA API to dump registry hives on remote computer☆18Mar 4, 2023Updated 3 years ago
- A work in progress BOF/COFF loader in Rust☆50Mar 22, 2023Updated 3 years ago
- UAC Bypass via CMUACUtil & PEB Enumeration, Undetected for now.☆52May 8, 2024Updated 2 years ago
- load dumped csharp binaries as assemblies and launch them in memory☆28Feb 9, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Repository to gather the .NET malware I will be developing☆20Mar 7, 2026Updated 5 months ago
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆260May 10, 2023Updated 3 years ago
- An App Domain Manager Injection DLL PoC on steroids☆216Dec 14, 2023Updated 2 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆710Jul 16, 2026Updated 3 weeks ago
- Code snippets to add on top of cobalt strike sleep mask to achieve patchless hook on AMSI and ETW☆88Mar 19, 2023Updated 3 years ago
- Lateral Movement via the .NET Profiler☆101Nov 21, 2024Updated last year
- A string obfuscator for .NET apps, built to evade static string analysis.☆108Jan 3, 2023Updated 3 years ago
- The code is a pingback to the Dark Vortex blog:☆190Jan 26, 2023Updated 3 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆146Jun 12, 2026Updated last month
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- DLL sideloading techniques for stealthy payload execution on Windows☆94Sep 20, 2023Updated 2 years ago
- C# havoc implant☆100Feb 12, 2023Updated 3 years ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆197Mar 14, 2025Updated last year
- Use TpAllocWork, TpPostWork and TpReleaseWork to execute machine code☆24Mar 13, 2023Updated 3 years ago
- Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations☆167Mar 1, 2024Updated 2 years ago
- Running .NET from VBA☆147Feb 11, 2023Updated 3 years ago
- YouTube/Livestream project for obfuscating C# source code using Roslyn☆128May 9, 2021Updated 5 years ago