xforcered / WFH
☆185Updated 2 years ago
Alternatives and similar repositories for WFH:
Users that are interested in WFH are comparing it to the libraries listed below
- Load any Beacon Object File using Powershell!☆246Updated 3 years ago
- InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assem…☆185Updated 3 years ago
- ☆215Updated 2 years ago
- Simple EDR implementation to demonstrate bypass☆163Updated 4 years ago
- ☆358Updated 3 years ago
- Apply a filter to the events being reported by windows event logging☆260Updated 3 years ago
- ☆204Updated 2 years ago
- Hookers are cooler than patches.☆168Updated 3 years ago
- A tool to find folders excluded from AV real-time scanning using a time oracle☆231Updated 11 months ago
- Koppeling x Metatwin x LazySign☆205Updated 3 years ago
- 64bit Windows 10 shellcode that injects all processes with Meterpreter reverse shells.☆128Updated last year
- A fake AMSI Provider which can be used for persistence.☆141Updated 3 years ago
- An effort to track security vendors' use of Microsoft's Antimalware Scan Interface☆238Updated 2 years ago
- ☆144Updated last year
- ☆376Updated 2 years ago
- A new AMSI Bypass technique using .NET ALI Call Hooking.☆186Updated 2 years ago
- Fully modular persistence framework☆249Updated last year
- PowerShell Constrained Language Mode Bypass☆242Updated 3 years ago
- LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript☆328Updated 3 years ago
- WNF Code Execution Library Using C#☆108Updated 4 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆234Updated 3 years ago
- Bypassing AppLocker with C#☆137Updated 3 years ago
- C# Implementation of the Hell's Gate VX Technique☆208Updated 4 years ago
- Weaponising C# - Fundamentals Training Content☆70Updated 3 years ago
- Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely☆408Updated 2 years ago
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆255Updated 2 years ago
- ☆111Updated last year
- COFF file (BOF) for managing Kerberos tickets.☆286Updated last year
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆317Updated 11 months ago
- Identifies the bytes that Microsoft Defender flags on.☆79Updated 2 years ago