xforcered / WFH
☆188Updated 2 years ago
Alternatives and similar repositories for WFH:
Users that are interested in WFH are comparing it to the libraries listed below
- InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assem…☆186Updated 3 years ago
- Simple EDR implementation to demonstrate bypass☆168Updated 4 years ago
- Koppeling x Metatwin x LazySign☆206Updated 3 years ago
- ☆206Updated 3 years ago
- Apply a filter to the events being reported by windows event logging☆261Updated 3 years ago
- Load any Beacon Object File using Powershell!☆246Updated 3 years ago
- Bypassing AppLocker with C#☆138Updated 3 years ago
- 64bit Windows 10 shellcode that injects all processes with Meterpreter reverse shells.☆128Updated last year
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆238Updated 3 years ago
- ☆375Updated 2 years ago
- ☆363Updated 3 years ago
- A tool to find folders excluded from AV real-time scanning using a time oracle☆232Updated last year
- LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript☆329Updated 3 years ago
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆256Updated 2 years ago
- Bring your own print driver privilege escalation tool☆247Updated 3 years ago
- ☆214Updated 2 years ago
- ☆96Updated 4 months ago
- C# Implementation of the Hell's Gate VX Technique☆210Updated 4 years ago
- An effort to track security vendors' use of Microsoft's Antimalware Scan Interface☆242Updated 3 years ago
- A fake AMSI Provider which can be used for persistence.☆147Updated 3 years ago
- Hookers are cooler than patches.☆168Updated 3 years ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆385Updated 11 months ago
- ☆297Updated last year
- RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows☆7Updated 2 years ago
- COFF file (BOF) for managing Kerberos tickets.☆290Updated last year
- ☆147Updated 3 weeks ago
- Dump stuff without touching disk☆163Updated 4 years ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆321Updated last year
- WNF Code Execution Library Using C#☆108Updated 4 years ago
- Fully modular persistence framework☆251Updated last year