
ExecuteAssembly
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…
command-and-controlexploitationids-ips-evasion+8
598

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

My experiments in weaponizing Nim (https://nim-lang.org/)

Code execution/injection technique using DLL PEB module structure manipulation