Pinned Loading
-
LibTP_Gadget
LibTP_Gadget PublicForked from rasta-mouse/LibTP
Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.
-
AlmondOffSec/LibTPLoadLib
AlmondOffSec/LibTPLoadLib PublicUsing call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared library. Format inspired by @rasta-mouse's LibTP.
-
AlmondOffSec/DCOMRunAs
AlmondOffSec/DCOMRunAs PublicLateral movement with DCOM DLL hijacking
-
HookDetector
HookDetector PublicHookDetector identifies DLL-imported functions that have been hooked in its own process.
C 1
-
-
Get-ModifiablePathFromProcmon
Get-ModifiablePathFromProcmon PublicA simple PowerShell function parsing a Procmon CSV output to extract accessed filesystem and registry paths and using @itm4n's PrivescCheck's functions `Get-ModifiablePath` and `Get-ModifiableRegis…
PowerShell 1
If the problem persists, check the GitHub status page or contact support.

