zha0gongz1 / weakenDefenderPriv
Without closing windows defender, to make defender useless by removing its token privileges and lowering the token integrity.
☆31Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for weakenDefenderPriv
- Use CMSTP.exe to bypass UAC.☆39Updated 2 years ago
- Change hash for a signed pe☆15Updated last year
- A PoC of Stack encryption prior to custom sleeping by leveraging CPU cycles.☆55Updated last year
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆61Updated 2 years ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆39Updated 11 months ago
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆58Updated 3 years ago
- ☆51Updated last year
- ☆44Updated 2 years ago
- ☆35Updated last year
- Code snippets to add on top of cobalt strike sleepmask kit so that ekko can work in a CFG protected process☆41Updated last year
- A basic C2 framework written in C☆58Updated 4 months ago
- Persistence via Shell Extensions☆62Updated last year
- Indirect NT syscalls LSASS dumper.☆36Updated last year
- Exploits undocumented elevated COM interface ICMLuaUtil via process spoofing to edit registry then calls ColorDataProxy to trigger UAC b…☆135Updated 2 years ago
- Simple reverse shell to avoid Windows defender and kaspersky detection☆18Updated 2 years ago
- Basic implementation of Cobalt Strikes - User Defined Reflective Loader feature☆95Updated last year
- ELF Beacon Object File (BOF) Template☆43Updated this week
- Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.☆32Updated last year
- This is a simple project made to evade https://github.com/thefLink/Hunt-Sleeping-Beacons by using a busy wait instead of beacon's built i…☆30Updated 2 years ago
- ☆62Updated 9 months ago
- Section Mapping Process Injection modified with SysWhisper2 (sw2-secinject): Cobalt Strike BOF☆41Updated 2 years ago
- Using LNK files and user input simulation to start processes under explorer.exe☆23Updated 2 months ago
- Golang implementation of @CCob's C# ThreadlessInject☆30Updated 6 months ago
- HookDetection☆44Updated 3 years ago
- It stinks☆100Updated 2 years ago
- Reflective DLL injection Execution☆19Updated 2 years ago
- A Cobalt Strike memory evasion loader for redteamers☆95Updated last year