Solomon Sklash's repositories

SleepyCrypt

A shellcode function to encrypt a running process image when sleeping.

Language:CLicense:GPL-3.0Stargazers:325Issues:5Issues:0

COM-Hijacking

An example of COM hijacking using a proxy DLL.

Language:C++Stargazers:20Issues:3Issues:0
Language:C++License:GPL-3.0Stargazers:20Issues:3Issues:0

RAII-types

Code to handle certain Windows types using the RAII paradigm

Stargazers:2Issues:0Issues:0

ShellcodeFluctuation

An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents

Language:C++Stargazers:2Issues:0Issues:0

SourcePoint

SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.

Language:GoStargazers:1Issues:1Issues:0
Stargazers:0Issues:0Issues:0

BOF2shellcode

POC tool to convert CobaltStrike BOF files to raw shellcode

Language:CLicense:NOASSERTIONStargazers:0Issues:0Issues:0

Certipy

Python implementation for Active Directory certificate abuse

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

concealed_position

Bring your own print driver privilige escalation tool

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

ElusiveMice

Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind

Stargazers:0Issues:0Issues:0

HandleKatz

PIC lsass dumper using cloned handles

Language:CStargazers:0Issues:1Issues:0

Invoke-DLLClone

Koppeling x Metatwin x LazySign

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

Khepri

🔥🔥🔥Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.

Language:C++License:Apache-2.0Stargazers:0Issues:1Issues:0

LockdExeDemo

A demo of the relevant blog post: https://www.arashparsa.com/hook-heaps-and-live-free/

Stargazers:0Issues:0Issues:0

MemoryLoader

A .NET binary loader that bypasses AMSI

Stargazers:0Issues:0Issues:0

minhook

The Minimalistic x86/x64 API Hooking Library for Windows

License:NOASSERTIONStargazers:0Issues:0Issues:0

nmap-parse-output

Converts/manipulates/extracts data from a Nmap scan output.

Language:XSLTLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

Obfuscate

Guaranteed compile-time string literal obfuscation header-only library for C++14

License:UnlicenseStargazers:0Issues:0Issues:0

offensive-rpc

Offensive RPC PoC

Language:C++Stargazers:0Issues:1Issues:0
Stargazers:0Issues:0Issues:0

red_team_attack_lab

Red Team Attack Lab for TTP testing & research

Stargazers:0Issues:0Issues:0

ScareCrow

ScareCrow - Payload creation framework designed around EDR bypass.

Language:GoLicense:MITStargazers:0Issues:0Issues:0

ServiceMove-BOF

New lateral movement technique by abusing Windows Perception Simulation Service to achieve DLL hijacking code execution.

Stargazers:0Issues:0Issues:0
License:MITStargazers:0Issues:0Issues:0

ThreadStackSpoofer

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.

Language:C++Stargazers:0Issues:0Issues:0

TitanLdr

Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH

Language:CStargazers:0Issues:0Issues:0
License:MITStargazers:0Issues:0Issues:0

WinPwn

Automation for internal Windows Penetrationtest / AD-Security

Language:PowerShellLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

winrmdll

C++ WinRM API via Reflective DLL

Language:C++License:MITStargazers:0Issues:1Issues:0