This is your work, valued

Italy

Diego Capriotti

Expert
@naksyn

Pyramid. a tool to help operate in EDRs' blind spots

772

PythonMemoryModule. pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

340

DojoLoader. Generic PE loader for fast prototyping evasion techniques

246

ProcessStomping. A variation of ProcessOverwriting to execute shellcode on an executable's section

147

ModuleShifting. Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

135

Embedder. Embedder is a collection of sources in different languages to embed Python interpreter with minimal dependencies

124

talks. Repo containing my public talks

23

python-bof-runner. Python inline shellcode injector that could be used to run BOFs by leveraging BOF2shellcode

8

UnhookingPatch. Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime

4

BouncyGate. HellsGate in Nim, but making sure that all syscalls go through NTDLL.DLL (as in RecycledGate).

3

DropSpawn_BOF. CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

2

DInjector. Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL

2

OffensivePipeline. OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.

1

DarkLoadLibrary. LoadLibrary for offensive operations

1

GregsBestFriend. GregsBestFriend process injection code created from the White Knight Labs Offensive Development course

1

Packer_Development. Slides & Code snippets for a workshop held @ x33fcon 2024

1

RWX-Dlls-for-manual-mapping. Here are a few rwx dlls your can use to manual map your cheat dll, they will prob get checked soon...

1

Havoc-C2-Modification-YARA-Free. POC of modifying YARA signautre for Havoc C2

1

FilelessRemotePE. Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique

1

FOLIAGE. Public variation of FOLIAGE ( original developer )

1

grimreaper. A improved memory obfuscation primitive using a combination of special and 'normal' Asynchronous Procedural Calls

1

TitanLdr. Public variation of Titan Loader

1

beacon. Former attempt at creating a independent Cobalt Strike Beacon

1