A proof-of-concept User-Defined Reflective Loader (UDRL) which aims to recreate, integrate, and enhance Cobalt Strike’s evasion features! Contributors: UDRL Usage …


A proof-of-concept User-Defined Reflective Loader (UDRL) which aims to recreate, integrate, and enhance Cobalt Strike’s evasion features! Contributors: UDRL Usage …
TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology. TripleCross is inspired by previous …
Authored By Tyl0us Featured at Source Zero Con 2022 Mangle is a tool that manipulates aspects of compiled executables (.exe …
Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via …
pamspy leverage eBPF technologies to achieve an equivalent work of 3snake. It will track a particular userland function inside the …
A flexible tool that creates a minidump of the LSASS process. 1. Features It uses syscalls (with SysWhispers2) for most …
EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Kernel callbacks and …
A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific modules or …
This tool implements a userland exploit that was initially discussed by James Forshaw (a.k.a. @tiraniddo) – in this blog post …
SysWhispers helps with evasion by generating header/ASM files implants can use to make direct system calls. All core syscalls are …