Skip to content
View ndur0's full-sized avatar

Block or report ndur0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
  • bofs Public

    Cobalt Strike BOF projects

    C 4 GNU General Public License v2.0 Updated Mar 29, 2021
  • SCShell Public

    Forked from Mr-Un1k0d3r/SCShell

    Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

    C Updated Mar 13, 2021
  • C# Updated Mar 12, 2021
  • Leverage existing 'GenericAll' AD rights over an object ie: user to set their profile to an attacker smb server ie: ntlmrelayx to dump hashes, relay, crack.

    C# Updated Feb 9, 2021
  • Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)

    Assembly Updated Jan 13, 2021
  • gowitness Public

    Forked from sensepost/gowitness

    🔍 gowitness - a golang, web screenshot utility using Chrome Headless

    Go GNU General Public License v3.0 Updated Nov 11, 2020
  • SharpBlock Public

    Forked from CCob/SharpBlock

    A method of bypassing EDR's active projection DLL's by preventing entry point exection

    C# Updated Aug 31, 2020
  • ScheduleMe Public

    The ScheduleMe project is part of establishing persistence via the WptsExtensions.dll DLL hijack.

    C# 1 GNU General Public License v3.0 Updated Aug 31, 2020
  • LightsOut Public

    PE Header, ETW, AMSI Evasion .net library (dll) utilizing SharpSploits' DInvoke to build / add to payloads

    C# GNU General Public License v3.0 Updated Aug 25, 2020
  • Collection of Offensive C# Tooling

    C# Updated Aug 13, 2020
  • PEzor Public

    Forked from phra/PEzor

    Read the blog post here: https://iwantmore.pizza/posts/PEzor.html

    C GNU General Public License v3.0 Updated Jul 23, 2020
  • x0rro Public

    Forked from phra/x0rro

    A PE/ELF/MachO Crypter for x86 and x86_64 Based on Radare2

    TypeScript Updated Jul 21, 2020
  • D/Invoke port of UrbanBishop

    C# BSD 3-Clause "New" or "Revised" License Updated Jul 19, 2020
  • C++ GNU General Public License v3.0 Updated Jul 13, 2020
  • Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.

    Updated Jul 13, 2020
  • WSMan-WinRM Public

    Forked from bohops/WSMan-WinRM

    A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

    C++ BSD 3-Clause "New" or "Revised" License Updated Jul 10, 2020
  • sgn Public

    Forked from EgeBalci/sgn

    Shikata ga nai (仕方がない) encoder ported into go with several improvements

    Go MIT License Updated Jul 7, 2020
  • NetLoader Public

    Forked from Flangvik/NetLoader

    Loads any C# binary in mem, patching AMSI and bypassing Windows Defender

    C# Updated Jul 2, 2020
  • SharpSploit Public

    Forked from cobbr/SharpSploit

    SharpSploit is a .NET post-exploitation library written in C#

    C# BSD 3-Clause "New" or "Revised" License Updated Jun 29, 2020
  • Evasor Public

    Forked from cyberark/Evasor

    A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

    C# Apache License 2.0 Updated Jun 25, 2020
  • My musings with C#

    C# BSD 3-Clause "New" or "Revised" License Updated Jun 15, 2020
  • UsoDllLoader Public

    Forked from itm4n/UsoDllLoader

    Windows - Weaponizing privileged file writes with the Update Session Orchestrator service

    C++ Updated Jun 6, 2020
  • Sniper Public

    Forked from dmchell/Sniper

    A simple proof of concept for detecting use of Cobalt Strike's execute-assembly

    C# Updated Jun 2, 2020
  • A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.

    C# GNU General Public License v3.0 Updated Apr 20, 2020
  • darkarmour Public

    Forked from bats3c/darkarmour

    Windows AV Evasion

    Python MIT License Updated Apr 13, 2020
  • Evade sysmon and windows event logging

    C MIT License Updated Apr 8, 2020
  • C# remote process injection utility for Cobalt Strike

    C# Updated Mar 9, 2020
  • Toolbox containing research notes & PoC code for weaponizing .NET's DLR

    PowerShell BSD 3-Clause "New" or "Revised" License Updated Feb 4, 2020
  • SharpGen Public

    Forked from cobbr/SharpGen

    SharpGen is a .NET Core console application that utilizes the Rosyln C# compiler to quickly cross-compile .NET Framework console applications or libraries.

    C# BSD 3-Clause "New" or "Revised" License Updated Dec 29, 2019
  • Objective-C MIT License Updated Dec 16, 2019