This is your work, valued
Offensive Security
BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW.
516SessionHop. Windows Session Hijacking via COM
349RemoteMonologue. Weaponizing DCOM for NTLM Authentication Coercions
215CVE-2023-27470_Exercise. C++
10WMImplant. This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.
3GodPotato. C#
3Screenshottery. Simple spyware that takes screenshots on target computer every "x" amount of seconds.
2Alaris. A protective and Low Level Shellcode Loader the defeats modern EDR systems.
1BlockEtw. .Net Assembly to block ETW telemetry in current process
1