TrustedPath-UACBypass-BOF

UAC Bypass Tool

Tools and techniques to bypass Windows UAC restrictions on executable files by utilizing DCOM objects

Cobalt Strike beacon object file implementation for trusted path UAC bypass. The target executable will be called without involving "cmd.exe" by using DCOM object.

GitHub

119 stars
5 watching
38 forks
Language: C
last commit: about 5 years ago

Related projects:

RepositoryDescriptionStars
octoberfest7/eventvieweruac_bofA tool that bypasses UAC restrictions on Windows by deserializing and executing malicious code in Event Viewer.129
encodegroup/uac-silentcleanA technique to bypass Windows UAC security restrictions using a DLL planting method for executing malicious code in high integrity processes.190
riccardoancarani/bofsUtilities for Cobalt Strike's Beacon Object Files to simplify working with shellcode and system processes112
airbus-cert/invoke-bofLoads and executes a malicious payload in a Windows system using PowerShell.245
boku7/injectetwbypassTool to bypass ETW (Event Tracing for Windows) security measure in remote processes by injecting a custom syscall276
cobalt-strike/bof-vsA Beacon Object File Visual Studio template project for creating malicious code executables145
boku7/injectamsibypassA tool that bypasses AMSI in a remote process with code injection.377
cobalt-strike/unhook-bofRemoves API hooks from a malicious process54
zu1k/beacon_hook_bypass_memscanBypassing memory scanning to evade detection by the Karbenz CASB (Content Awareness Security Platform) security solution24
dimopouloselias/alpc-mmc-uac-bypassExploits ALPC and mmc to bypass Windows UAC for administrative privileges.155
0x3rhy/adduser-bofA Cobalt Strike BOF that exploits a vulnerability to add an admin user70
ccob/bof.netA .NET runtime framework for developing and executing malicious C code in a managed environment.682
bohops/ultimatewdacbypasslistA centralized resource for bypassing Windows Device Guard Application Whitelisting (WDAC) policies.489
mlcsec/asrenum-bofTools to detect and exploit vulnerabilities in Windows Attack Surface Reduction (ASR) settings142
northwavesecurity/kernel-miiExploits a kernel vulnerability to gain SYSTEM privileges on Windows.29