Category: Exploitation

polyglot payload generator

SNOWCRASH: polyglot payload generator

SNOWCRASH – polyglot payload generator SNOWCRASH creates a script that can be launched on both Linux and Windows machines. Payload selected by the user (in this case combined Bash and...

CobaltStrike BOF

CobaltStrike BOF: Collection of beacon BOF

CobaltStrike BOF Collection of beacon BOF. 1 ) DCOM Lateral Movement A quick PoC that uses DCOM (ShellWindows) via beacon object files for lateral movement. You can either specify credentials...

Bad Outlook

Bad Outlook: Malicious Outlook Reader

Bad Outlook A simple PoC which leverages the Outlook Application Interface (COM Interface) to execute shellcode on a system based on a specific trigger subject line. By utilizing Microsoft.Office.Interop.Outlook namespace, developers...

UnhookMe

UnhookMe: Dynamically unhooking imports resolver

UnhookMe – Dynamically unhooking imports resolver In the era of intrusive AVs and EDRs that introduce hot-patches to the running processes for their enhanced optics requirements, modern adversaries must have...