Lefteris Panos's repositories

3aj-lib

Proof of concept communications from C# via a web browser process

License:MITStargazers:0Issues:0Issues:0

acCOMplice

Tools for discovery and abuse of COM hijacks

License:NOASSERTIONStargazers:0Issues:0Issues:0

citrix-printer-exfil

POC to Exfiltrate Data from Citrix using Client Printer Redirection

Stargazers:0Issues:0Issues:0

COMInterop

Example on how to consume a COM server from a .NET client and a .NET server from a COM client. Examples are for both using the Registry and for RegFree.

Stargazers:0Issues:0Issues:0

CSharpSetThreadContext

C# Shellcode Runner to execute shellcode via CreateRemoteThread and SetThreadContext to evade Get-InjectedThread

Stargazers:0Issues:0Issues:0

DanSpecial

Weaponizing Gigabyte driver for priv escalation and bypass PPL

Stargazers:0Issues:0Issues:0

DLLFromMemory-net

C# library to load a native DLL from memory without the need to allow unsafe code

License:MPL-2.0Stargazers:0Issues:0Issues:0

dnSpy

.NET debugger and assembly editor

Language:C#Stargazers:0Issues:0Issues:0

instrumentation-callbacks

based on https://github.com/secrary/Hooking-via-InstrumentationCallback

Stargazers:0Issues:0Issues:0

Lepus

Subdomain finder

Language:PythonLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

Malproxy

Proxy system calls over an RPC channel

Stargazers:0Issues:0Issues:0

NET-Assembly-Inject-Remote

.NET assembly local/remote loading/injection into memory.

Stargazers:0Issues:0Issues:0

physmem_drivers

A collection of various vulnerable (mostly physical memory exposing) drivers.

Stargazers:0Issues:0Issues:0

Random-CSharpTools

Collection of CSharp Assemblies focused on Post-Exploitation Capabilities

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

ReflectiveDLLRefresher

Universal Unhooking

License:NOASSERTIONStargazers:0Issues:0Issues:0

RunDllMShim

Run Managed Assemblies with RunDll

License:MITStargazers:0Issues:0Issues:0

SharpDoor

SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.

License:Apache-2.0Stargazers:0Issues:0Issues:0

SharpGPOAbuse

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.

Stargazers:0Issues:0Issues:0

SharpSpray

SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike.

Stargazers:0Issues:0Issues:0

ShellcodeStdio

An extensible framework for easily writing compiler optimized position independent x86 / x64 shellcode for windows platforms.

License:GPL-2.0Stargazers:0Issues:0Issues:0

silentbridge

Silentbridge is a toolkit for bypassing 802.1x-2010 and 802.1x-2004.

License:GPL-3.0Stargazers:0Issues:0Issues:0

slurp

The original slurp source

License:AGPL-3.0Stargazers:0Issues:0Issues:0

spoofing-office-macro

:fish: PoC of a VBA macro spawning a process with a spoofed parent and command line.

Language:Visual BasicLicense:AGPL-3.0Stargazers:0Issues:0Issues:0

SpoolSample

PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

SvcHostDemo

Demo service that runs in svchost.exe

Language:C++License:MITStargazers:0Issues:1Issues:0

thotcon0xa

Content from THOTCON 0xa talk

License:MITStargazers:0Issues:0Issues:0

TRunPE

A modified RunPE (process hollowing) technique avoiding the usage of SetThreadContext by appending a TLS section which calls the original entrypoint.

License:GPL-3.0Stargazers:0Issues:0Issues:0

urban-dictionary-word-list

Script and sample dataset of all urban dictionary entry names (around 1.4 million total)

License:MITStargazers:0Issues:0Issues:0

vulcan

a tool to make it easy and fast to test various forms of injection

Stargazers:0Issues:0Issues:0