DamonMohammadbagher
Security Researcher "https://damonmohammadbagher.github.io" , "https://medium.com/@damonmohammadbagher"
Pinned Repositories
BEV4
BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detections via yaml files
eBook-BypassingAVsByCSharp
eBook "Bypassing AVS by C#.NET Programming" (Free Chapters only)
eBook_Bypassing-Antiviruses-by-C-Programming-v2.0
bypassing Anti-viruses by csharp programming v2.0
ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Meterpreter_Payload_Detection
Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool
NativePayload_CBT
NativePayload_CallBackTechniques C# Codes (Code Execution via Callback Functions Technique, without CreateThread Native API)
NativePayload_DNS
C# code for Transferring Backdoor Payloads by DNS Traffic and Bypassing Anti-viruses
NativePayload_Reverse_tcp
Meterpreter Encrypted Payload by C#
NativePayloads
All my Source Codes (Repos) for Red-Teaming & Pentesting + Blue Teaming
Some_Pentesters_SecurityResearchers_RedTeamers
Some Pentesters, Security Researchers, Red Teamers which i learned from them a lot...
DamonMohammadbagher's Repositories
DamonMohammadbagher/eBook-BypassingAVsByCSharp
eBook "Bypassing AVS by C#.NET Programming" (Free Chapters only)
DamonMohammadbagher/ETWProcessMon2
ETWProcessMon2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
DamonMohammadbagher/NativePayloads
All my Source Codes (Repos) for Red-Teaming & Pentesting + Blue Teaming
DamonMohammadbagher/NativePayload_Reverse_tcp
Meterpreter Encrypted Payload by C#
DamonMohammadbagher/NativePayload_CBT
NativePayload_CallBackTechniques C# Codes (Code Execution via Callback Functions Technique, without CreateThread Native API)
DamonMohammadbagher/Some_Pentesters_SecurityResearchers_RedTeamers
Some Pentesters, Security Researchers, Red Teamers which i learned from them a lot...
DamonMohammadbagher/FakeFileMaker
Social Engineering: Simple way to make a fake file for Backdoors
DamonMohammadbagher/BEV4
BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detections via yaml files
DamonMohammadbagher/NativePayload_DIM
NativePayload_DIM Dynamic native dll Injection in Memory , Injecting Native DLL bytes to local Process
DamonMohammadbagher/NativePayload_TiACBT
NativePayload_TiACBT (Remote Thread Injection + C# Async Method + CallBack Functions Technique)
DamonMohammadbagher/NativePayload_DCP
Compiling Csharp in-memory and Execute to bypass AVs
DamonMohammadbagher/eBook_Bypassing-Antiviruses-by-C-Programming-v2.0
bypassing Anti-viruses by csharp programming v2.0
DamonMohammadbagher/Exfiltration-and-Uploading-DATA-by-DNS-Traffic-AAAA-Records-
Pdf File : Exfiltration and Uploading DATA by DNS Traffic (AAAA Records)
DamonMohammadbagher/NativePayload_LocalCreateThread7
Chunking CobaltStrike Payloads + Jump Method
DamonMohammadbagher/RedbudTree
DNS IPv6 Request Listener (UDP Port 53) for Detecting Exfiltration DATA via IPv6 DNS AAAA Record Requests
DamonMohammadbagher/backdoorppt
transform your payload.exe into one fake word doc (.ppt)
DamonMohammadbagher/damonmohammadbagher.github.io
DamonMohammadbagher/FSWatch
File System Watcher via C# (Monitoring File Activity , Create/Delete/Change/Rename events + some Activity like Size/Attribute/Security Changes & LastAccess, LastWrite etc...)
DamonMohammadbagher/NativePayload_CTX
NativePayload_CTX Create Thread via _beginthreadex function in msvcrt.dll
DamonMohammadbagher/Payload-hiding-Method-via-Infecting-Target-Process-Memory
DamonMohammadbagher/NativePayload_CDynApp3
Loading Csharp C2 Client-side codes in RAM by Very Simple New Technique to avoid Detection
DamonMohammadbagher/NativePayload_NetMonitor
NativePayload_NetMonitor Monitoring NetworkTraffic over [ICMP/ARP/TCP/UDP + HTTP + DNS] by ws2_32.dll Windows Sockets Library
DamonMohammadbagher/NativePayload_RefPtr1
NativePayload_RefPtr1 Indirect call csharp method in memory [without call c# method in source code directly]
DamonMohammadbagher/NativePayload_ASM3
NativePayload_ASM/AsynASM , Injecting Meterpreter Payload bytes into local Process via Delegation Technique [Technique D] + in-memory with delay Changing RWX to X [Bypassing AVs]
DamonMohammadbagher/Manifest-Creator
C# tool for make XML report from Network Hosts (report contains: Cpu,Bios,Motherboard,Vga,Sound,Hdd,Ram,Display-Monitor,IpAddress,Os,Users,...)
DamonMohammadbagher/NativePayload_JMP4
in C# you can use Emit(Opcodes.jmp,TargetMethod) in your codes without writing any asm bytes in code to jump to pointer of TargetMethod or (MethodInfo) to run in-memory via Emit(Opcodes.jmp, method) in system.reflection namespace
DamonMohammadbagher/DamonMohammadbagher
DamonMohammadbagher/NativePayload_DYN
Compiling Csharp in-memory and Execute to bypass AVs
DamonMohammadbagher/NativePayload_PingSend
NativePayload_PingSend send data/string (exfiltration) to destination ip via icmp ping packets
DamonMohammadbagher/NativePayload_Call4
NativePayload_Call4 Emit Call Method + Indirect Invoke C# Method "Emit(Opcodes.Call)" instead "Emit(Opcodes.Jmp)"