
GhostTrace
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Assist reverse tcp shells in post-exploration tasks

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

.NET tool for installing Windows persistence via registry keys, scheduled tasks, services, WMI events, COM hijacks, and LNK backdoors, supporting…

C# tool for establishing Windows persistence via multiple techniques including scheduled tasks, WMI events, startup folders, and registry hijacking,…

C# toolkit for establishing and managing Windows persistence via registry keys, scheduled tasks, services, startup folders, KeePass configs, and…

A BOF to automate common persistence tasks for red teamers

Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Cobalt Strike extension for post-exploitation persistence using SharpStay .NET assembly. Provides GUI-driven persistence via Registry keys, Scheduled…

A collection of AWS penetration testing junk