xct / diaghub
Loads a custom dll in system32 via diaghub.
☆68Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for diaghub
- POC for NetworkService PrivEsc☆123Updated 4 years ago
- This code was used for the blogpost on secjuice.☆40Updated 5 years ago
- MiniDumpWriteDump behavior modification hook☆49Updated 3 years ago
- C# PoC implementation for bypassing AMSI via in memory patching☆66Updated 4 years ago
- Simple APPLocker bypass summary☆39Updated 6 years ago
- ☆54Updated 2 years ago
- Implementation of b4rtiks's SharpMiniDump using NTFS transactions to avoid writting the minidump to disk and exfiltrating it via HTTPS us…☆68Updated 3 years ago
- credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege☆121Updated 3 years ago
- ☆90Updated 3 years ago
- (kinda) Malicious Outlook Reader☆133Updated 3 years ago
- Impersonating authentication over HTTP and/or named pipes.☆119Updated 3 years ago
- AMSI Bypass Via the Heap☆105Updated 3 years ago
- MSBuild without MSbuild.exe☆128Updated 3 years ago
- Tool for interacting with outlook interop during red team engagements☆143Updated 3 years ago
- ☆26Updated last year
- Checks for signature requirements over LDAP☆92Updated 2 years ago
- ☆43Updated 7 years ago
- A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from …☆83Updated 4 years ago
- ☆147Updated 4 years ago
- A sort of simple shell which support multiple protocols.☆99Updated 5 years ago
- Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2☆178Updated 2 years ago
- named pipe server with impersonation☆56Updated 5 years ago
- Pass the Hash to a named pipe for token Impersonation☆140Updated 3 years ago
- Source code for HppDLL - local password dumping using MsvpPasswordValidate hooks☆1Updated 3 years ago
- Suite of Shellcode Running Utilities☆106Updated 4 years ago
- Proof-of-concept code for various bugs☆106Updated last week
- A Collection of templates that can be used for abusing window's AlwaysInstallElevated policy☆26Updated last year