seahop
Red Teamer. Just out here creating some simple PoCs for red teamy things. Amateur coder. No best practices here.
United States
Pinned Repositories
CPP_XOR
getPIDIntegrity
Injection
mimiRust
All credits to: github.com/ThottySploity/mimiRust (Original author deleted account so I uploaded for community use)
patchETW
Function to patch ETW with syscalls
RemoteProcDLLInject
RemoteShellcodeInjection_XOR
SyscallProcScan
Syscall process scanner
titan
Titan: A generic user defined reflective DLL for Cobalt Strike
seahop's Repositories
seahop/Supernova
Real fucking shellcode encryption tool.
seahop/API-Hashing
A basic exemple of the API-Hashing method used by Red Teamers but also by malwares developers in C++
seahop/arm64_macOS_Syscalls
seahop/BokuLoader
Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities. By: @0xBoku & @s4ntiago_p
seahop/BounceBack
↕️🤫 Stealth redirector for your red team operation security
seahop/C2-Tool-Collection
A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
seahop/Click-Once-App-Domain-Injection
Click Once + App Domain
seahop/ContainYourself
A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.
seahop/cookie-monster
BOF to steal browser cookies & credentials
seahop/CVE-2023-36874
CVE-2023-36874 PoC
seahop/CVE-2023-36874_BOF
Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE
seahop/Defender-Exclusions-Creator-BOF
seahop/EDRSandblast-GodFault
EDRSandblast-GodFault
seahop/HeaderLessPE
seahop/KBlast
Windows Kernel Offensive Toolset
seahop/LatLoader
PoC module to demonstrate automated lateral movement with the Havoc C2 framework.
seahop/LdrLockLiberator
For when DLLMain is the only way
seahop/Mockingjay_BOF
Cobalt Strike Beacon Object File (BOF) Conversion of the Mockingjay Process Injection Technique
seahop/moonshine
seahop/NetExec
The Network Execution Tool
seahop/odin
odin c2
seahop/PoolParty
A set of fully-undetectable process injection techniques abusing Windows Thread Pools
seahop/Proxycalls
miscellaneous codes
seahop/RandomTSScripts
Collection of random RedTeam scripts.
seahop/SharpBlackout
Terminate AV/EDR leveraging BYOVD attack
seahop/SharpKiller
Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8
seahop/SimpleEDR
Simple EDR that injects a DLL into a process to place a hook on specific Windows API
seahop/Split
Apply a divide and conquer approach to bypass EDRs
seahop/tweetter
Simple Twitter Bot, made with Selenium and JavaScript.
seahop/Windows-Internals
Important notes and topics on my journey towards mastering Windows Internals