xpn / WAMBam
Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post
☆110Updated last year
Related projects ⓘ
Alternatives and complementary repositories for WAMBam
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆86Updated 2 years ago
- ☆139Updated last year
- ☆83Updated 2 years ago
- Lockless BOF☆62Updated 9 months ago
- A BOF to interact with COM objects associated with the Windows software firewall.☆100Updated 3 years ago
- Collection of Beacon Object Files (BOFs) for shells and lols☆112Updated 3 years ago
- Implant drop-in for EDR testing☆128Updated last year
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆59Updated last month
- Lateral Movement via the .NET Profiler☆76Updated 5 months ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆87Updated 2 years ago
- ☆61Updated 2 years ago
- Simple BOF to read the protection level of a process☆104Updated last year
- ☆51Updated 3 years ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆88Updated last year
- Python module for running BOFs☆64Updated last year
- ☆68Updated 2 years ago
- Remove API hooks from a Beacon process.☆54Updated 2 years ago
- ☆133Updated last year
- Parse SDDL strings☆35Updated 7 months ago
- this repo is to cover the other undocumented or published / in different langaue to achieve shellcode injection via windows callback func…☆82Updated 2 years ago
- Beacon Object File allowing creation of Beacons in different sessions.☆76Updated 2 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆130Updated 2 months ago
- Cobalt Strike BOF for quser.exe implementation using Windows API☆83Updated last year
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- ☆67Updated 3 months ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- ☆91Updated 2 years ago