awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
0xEr3bus avatar

0xEr3bus/PoolPartyBof

0
View on GitHub↗
452 stars·52 forks·C·1 view

PoolPartyBof

A beacon object file implementation of PoolParty Process Injection Technique by @SafeBreach and @0xDeku, that abuses Windows Thread Pools. The BOF supports the 5 technique/variant: - Insert TPIO work item to the target process's thread pool. - Insert TPALPC work item to the target process's…

Features

  • Defense Evasion - Injects code using Windows Thread Pool abuse.

Star history

Star history chart for 0xer3bus/poolpartybofStar history chart for 0xer3bus/poolpartybof

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to PoolPartyBof

Similar open-source projects, ranked by how many features they share with PoolPartyBof.
  • lolbas-project/lolbasLOLBAS-Project avatar

    LOLBAS-Project/LOLBAS

    8,323View on GitHub↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    View on GitHub↗8,323
  • bats3c/darkloadlibrarybats3c avatar

    bats3c/DarkLoadLibrary

    1,180View on GitHub↗

    LoadLibrary for offensive operations

    C
    View on GitHub↗1,180
  • bats3c/evtmutebats3c avatar

    bats3c/EvtMute

    264View on GitHub↗

    This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event logging.

    C#
    View on GitHub↗264
  • aptortellini/undefenderAPTortellini avatar

    APTortellini/unDefender

    360View on GitHub↗

    unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its core, this technique revolves around changing the \Device\BootDevice symbolic link in the Windows Object Manager so that when Defender's WdFilter driver is unloaded and loaded…

    C++
    View on GitHub↗360
See all 30 alternatives to PoolPartyBof→

Frequently asked questions

What does 0xer3bus/poolpartybof do?

A beacon object file implementation of PoolParty Process Injection Technique by @SafeBreach and @0xDeku, that abuses Windows Thread Pools. The BOF supports the 5 technique/variant: - Insert TPIO work item to the target process's thread pool. - Insert TPALPC work item to the target process's…

What are the main features of 0xer3bus/poolpartybof?

The main features of 0xer3bus/poolpartybof are: Defense Evasion.

What are some open-source alternatives to 0xer3bus/poolpartybof?

Open-source alternatives to 0xer3bus/poolpartybof include: lolbas-project/lolbas — LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security… bats3c/darkloadlibrary — LoadLibrary for offensive operations. bats3c/evtmute — This is a tool that allows you to offensively use YARA to apply a filter to the events being reported by windows event… ccob/sharpblock. cerbersec/killdefenderbof — KillDefenderBOF is a Beacon Object File PoC implementation of pwn1sher/KillDefender which is based on research by… aptortellini/undefender — unDefender is the C++ implementation of a technique originally described by @jonasLyk in this Twitter thread. At its…