
Awesome-CobaltStrike
List of Awesome CobaltStrike Resources

List of Awesome CobaltStrike Resources

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

PowerShell scripts for communicating with a remote host.

Avoidz tool to bypass most A.V softwares

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

XIP generates a list of IP addresses by applying a set of transformations used to bypass security measures e.g. blacklist filtering, WAF, etc.

Asymmetric defense against adversarial AI agents. VeilGate evaluates each incoming request, redirects suspected agents into a per-IP-consistent…

A fake host that can be "managed" by Dell OMSA, getting you past the login screen.

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Lists of AMSI triggers (VBA, JScript / VBScript)

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

SysWhispers on Steroids - AV/EDR evasion via direct system calls.

Curated collection of offensive security tools and commands for Active Directory attacks, C2, privilege escalation, obfuscation, and web pentesting.