elp4tr0n's repositories
BeaconHunter
Detect and respond to Cobalt Strike beacons using ETW.
AceLdr
Cobalt Strike UDRL for memory scanner evasion.
CheeseOunce
Coerce Windows machines auth via MS-EVEN
CVE-2021-40444
CVE-2021-40444 PoC
DInvoke
Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.
DynamicWrapperDotNet
Dynamically Loads Assembly and Calls Methods from JScript
expbox
Vulnerability Exploitation Code Collection Repository
Ghostpack-CompiledBinaries
Compiled Binaries for Ghostpack (.NET v4.0)
InlineExecute-Assembly
InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module
merlin
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Mimikore
.NET 5 Single file Application
Ninja_UUID_Runner
Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!
OffensiveVBA
This repo covers some code execution and AV Evasion methods for Macros in Office documents
Pluto
A manual system call library that supports functions from both ntdll.dll and win32u.dll
PPLDump_BOF
A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.
route-sixty-sink
Link sources to sinks in C# applications.
S4UTomato
Escalate Service Account To LocalSystem via Kerberos
SharpCollection
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
SharpNamedPipePTH
Pass the Hash to a named pipe for token Impersonation
SyscallAmsiScanBufferBypass
AmsiScanBufferBypass using D/Invoke
titan
Titan: A generic user defined reflective DLL for Cobalt Strike
TitanLdr
Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH
WAMBam
Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post