


Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Reflective PE packer.

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

LoadLibrary for offensive operations

A tool for generating fake code signing certificates or signing real ones

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Adaptive DLL hijacking / dynamic export forwarding

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

Signtool for expired certificates

Automated DLL Sideloading Tool With EDR Evasion Capabilities

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

A C2 post-exploitation framework