zimnyaa / fiber-stager
A simple Nim stager (w/ fiber execution)
☆16Updated 2 years ago
Alternatives and similar repositories for fiber-stager:
Users that are interested in fiber-stager are comparing it to the libraries listed below
- Unused DLL hollowing PoC in Nim☆17Updated 2 years ago
- Another AMSI bypass - but in C++.☆23Updated last year
- Run python from a single exe☆34Updated 2 years ago
- A small example of loading BOFs in Python with pure reflection☆18Updated 2 years ago
- Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts☆17Updated last year
- A nim port of C5pider's Ekko project.☆17Updated 2 years ago
- C# project to Reflectively load .Net assemblies in memory☆17Updated 7 months ago
- Extension functionality for the NightHawk operator client☆26Updated last year
- Example of using Sleep to create better named pipes.☆41Updated last year
- ☆46Updated 3 years ago
- ☆47Updated last year
- Self Delete DLL☆23Updated 11 months ago
- Remove API hooks from a Beacon process.☆13Updated 3 years ago
- Miscellaneous examples for use with Cobalt Strike Beacon☆10Updated 4 years ago
- PoC XLL builder in Python/Nim☆43Updated 2 years ago
- NimSkrull is an adaption from the original Skrull malware anti-copy DRM. Only for the anti-copy feature. (https://github.com/aaaddress1/S…☆12Updated last year
- One gate to all syscalls!☆23Updated 2 years ago
- ShellcodeFluctuation PoC ported to Nim☆75Updated 2 years ago
- ☆26Updated 4 years ago
- A way to extract tickets in case I need to purge and restore tickets on the fly.☆17Updated 9 months ago
- Just another casual shellcode native loader☆24Updated 2 years ago
- Just another Process Injection using Process Hollowing technique.☆16Updated last year
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- Extended Process List (Search functionality)☆29Updated 4 years ago
- A reimplementation of Cobalt Strike's Beacon Object File (BOF) Loader☆41Updated last year
- PoC for detecting and evading ETW detection of .Net Assembly.Load☆18Updated 4 years ago
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies☆32Updated 2 years ago
- Golang Implementation of Hell's gate☆17Updated last year
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- A proof-of-concept created for academic/learning purposes, demonstrating both local and remote use of VSTO "Add-In's" maliciously☆31Updated last year