
aether
Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

DCOM in memory and fileless lateral movement techniques through .Net deserilization

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

A C# Command & Control framework

A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.

Payload Generation Framework

Remote Administration Tool for Windows

.NET/PowerShell/VBA Offensive Security Obfuscator

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.

CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。

.NET Project for Attacking vCenter

SharpSploit is a .NET post-exploitation library written in C#

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Covenant is a collaborative .NET C2 framework for red teamers.