elp4tr0n's repositories

BeaconHunter

Detect and respond to Cobalt Strike beacons using ETW.

Language:C#License:Apache-2.0Stargazers:2Issues:0Issues:0

AceLdr

Cobalt Strike UDRL for memory scanner evasion.

Language:CLicense:MITStargazers:0Issues:0Issues:0

CheeseOunce

Coerce Windows machines auth via MS-EVEN

Language:CStargazers:0Issues:0Issues:0

CVE-2021-40444

CVE-2021-40444 PoC

Stargazers:0Issues:0Issues:0

DInvoke

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Language:C#License:MITStargazers:0Issues:0Issues:0

DynamicWrapperDotNet

Dynamically Loads Assembly and Calls Methods from JScript

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

expbox

Vulnerability Exploitation Code Collection Repository

Language:PythonStargazers:0Issues:0Issues:0

Ghostpack-CompiledBinaries

Compiled Binaries for Ghostpack (.NET v4.0)

Stargazers:0Issues:0Issues:0

InlineExecute-Assembly

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

Stargazers:0Issues:0Issues:0

merlin

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

License:GPL-3.0Stargazers:0Issues:0Issues:0

Mimikore

.NET 5 Single file Application

Language:C#License:BSD-3-ClauseStargazers:0Issues:0Issues:0
License:Apache-2.0Stargazers:0Issues:0Issues:0

Ninja_UUID_Runner

Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!

Stargazers:0Issues:0Issues:0

OffensiveVBA

This repo covers some code execution and AV Evasion methods for Macros in Office documents

Language:VBALicense:BSD-2-ClauseStargazers:0Issues:0Issues:0
Language:C#License:Apache-2.0Stargazers:0Issues:0Issues:0

Pluto

A manual system call library that supports functions from both ntdll.dll and win32u.dll

Language:C#License:MITStargazers:0Issues:0Issues:0

PPLDump_BOF

A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

route-sixty-sink

Link sources to sinks in C# applications.

License:Apache-2.0Stargazers:0Issues:0Issues:0

S4UTomato

Escalate Service Account To LocalSystem via Kerberos

Stargazers:0Issues:0Issues:0

SharpCollection

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.

Stargazers:0Issues:0Issues:0

SharpNamedPipePTH

Pass the Hash to a named pipe for token Impersonation

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

SyscallAmsiScanBufferBypass

AmsiScanBufferBypass using D/Invoke

Stargazers:0Issues:0Issues:0

titan

Titan: A generic user defined reflective DLL for Cobalt Strike

Stargazers:0Issues:0Issues:0

TitanLdr

Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH

Stargazers:0Issues:0Issues:0

WAMBam

Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post

Language:C#Stargazers:0Issues:0Issues:0
Language:JavaScriptStargazers:0Issues:0Issues:0