Robert Wilson (0xRobert)

0xRobert

Geek Repo

0

followers

0

following

0

stars

Github PK Tool:Github PK Tool

Robert Wilson's repositories

IORI_Loader

UUID shellcode Loader with dynamic indirect syscall implementation, syscall number/instruction get resolved dynamicaly at runtime, and the syscall number/instruction get unhooked using Halosgate technique. Function address get resolved from the PEB by offsets and comparaison by hashes

Language:C++Stargazers:6Issues:0Issues:0

AtomPePacker

A Highly capable Pe Packer

Language:CLicense:Apache-2.0Stargazers:0Issues:0Issues:0

awesome-flipperzero

🐬 A collection of awesome resources for the Flipper Zero device.

License:CC0-1.0Stargazers:0Issues:0Issues:0

cmstplua-uac-bypass

Cobalt Strike Beacon Object File for bypassing UAC via the CMSTPLUA COM interface.

Language:CLicense:MITStargazers:0Issues:0Issues:0
Language:C++License:MITStargazers:0Issues:0Issues:0

dissect.cobaltstrike

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

DragonCastle

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Language:C++Stargazers:0Issues:0Issues:0

DriverNoImage

以shellcode注入其它驱动执行,躲避驱动签名检测,曾pubg项目中使用,,,当然现在,,,

Language:CStargazers:0Issues:0Issues:0

EDD

Enumerate Domain Data

Language:C#Stargazers:0Issues:0Issues:0

exe_who

Executables on Disk? Bleh 🤮

Language:RustStargazers:0Issues:0Issues:0

ExecRemoteAssembly

Execute Remote Assembly with args passing and with AMSI and ETW patching

Language:C++Stargazers:0Issues:0Issues:0

Firefox-WebInject

Firefox webInjector capable of injecting codes into webpages usint a mitmproxy.

Language:C++Stargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

geacon_pro

跨平台重构了Cobaltstrike Beacon,适配了大部分Beacon的功能,行为对国内主流杀软免杀,支持4.1以上的版本。 A cobaltstrike Beacon bypass anti-virus, supports 4.1+ version.

Language:GoStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Language:C++License:GPL-2.0Stargazers:0Issues:0Issues:0

llvm-msvc-build

Build llvm-msvc

License:GPL-3.0Stargazers:0Issues:0Issues:0

MCP-PoC

Minifilter Callback Patching Proof-of-Concept

Language:C++License:UnlicenseStargazers:0Issues:0Issues:0

NoRunPI

Run Your Payload Without Running Your Payload

Language:CLicense:MITStargazers:0Issues:0Issues:0

PassTheCert

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

Language:C#License:Apache-2.0Stargazers:0Issues:0Issues:0

RedEye

RedEye is a visual analytic tool supporting Red & Blue Team operations

Language:TypeScriptLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

ScreenshotBOF

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot saved to disk as a file.

Language:CStargazers:0Issues:0Issues:0

ShadowSpray

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.

Language:C#Stargazers:0Issues:0Issues:0

Spartacus

Spartacus DLL Hijacking Discovery Tool

Language:C#License:MITStargazers:0Issues:0Issues:0

SSN_Resolver

dynamically resolving System Service Number (syscall number) by offsets from the PEB with API hashing

Language:C++Stargazers:0Issues:0Issues:0

TerraLdr

A Payload Loader Designed With Advanced Evasion Features

Language:CLicense:Apache-2.0Stargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

vba2clr

Running .NET from VBA

Language:C#Stargazers:0Issues:0Issues:0

WAMBam

Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post

Language:C#Stargazers:0Issues:0Issues:0
Language:C#Stargazers:0Issues:0Issues:0