2-day longest streak
-
DVS
Damn Vulnerable Startup (DVS)
Python ★ 29 2mo agoExplain → -
ghosttype-bof
BOF that scans Claude Code, Cursor, Codex, and ChatGPT Desktop conversation histories for exposed credentials. Should work with any COFF-loader compatitble C2.
C ★ 15 2mo agoExplain → -
NorwegianPasswordSpraying
A repository containing lists and different combinations of weak/default passwords (in Norwegian) typically seen during external pentests and red team assessments. Contains seasons, months and holidays.
★ 5 3y agoExplain → -
DEATHCON-25-OPTE
Repository for the DEATHCon 2025 Workshop "Operationzaling Purple Teaming in the Enterprise".
★ 4 8mo agoExplain → -
Internal-Pentest-Playbook ⑂
Internal Network Penetration Test Playbook
PowerShell ★ 4 5y agoExplain → -
SharpC2
.NET C2 Framework Proof of Concept
★ 2 6y agoExplain → -
NimPlant ⑂
A light-weight first-stage C2 implant written in Nim.
Nim ★ 1 3y agoExplain → -
NetLoader ⑂
Loads any C# binary in mem, patching AMSI and bypassing Windows Defender
★ 1 6y agoExplain → -
Seatbelt ⑂
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
★ 1 7y agoExplain → -
awesome-burp-extensions ⑂
A curated list of amazingly awesome Burp Extensions
★ 1 6y agoExplain → -
HandsOnBloodHound ⑂
Material for the "Hands-On BloodHound" Workshop
★ 1 6y agoExplain → -
adrian ⑂
Open-source runtime security monitoring and control for AI agents.
Python ★ 0 24d agoExplain → -
PhantomCtx ⑂
Activation Context Hijacking Evasion Tool
★ 0 1mo agoExplain → -
ghosttype ⑂
Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
★ 0 2mo agoExplain → -
talks
Slides and other materials from talks.
★ 0 4mo agoExplain → -
phsite ⑂
POC - Phishing site generator
★ 0 2y agoExplain → -
awesome-threat-detection ⑂
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 0 2y agoExplain → -
BARK ⑂
BloodHound Attack Research Kit
★ 0 1y agoExplain → -
Sentinel ⑂
No description.
★ 0 2y agoExplain → -
lsassy ⑂
Extract credentials from lsass remotely
★ 0 6y agoExplain → -
import-custom-bloodhound-queries ⑂
Import custom queries into BloodHound CE from a legacy BloodHound JSON file.
★ 0 2y agoExplain → -
Mindmaps ⑂
Azure mindmap for penetration tests
★ 0 2y agoExplain → -
LinikatzV2 ⑂
Linikatz V2 is a bash script which allows post-exploitation tasks on UNIX computers joined to Active Directory
★ 0 2y agoExplain → -
MagicSigner ⑂
Signtool for expired certificates
★ 0 3y agoExplain → -
RemoteApp_1 ⑂
I have created this custom server for preparing EXP-301 course (aka WUMED) exam and hope it will help to take OSED certification. Feel free to DM me in discord, if you have any questions about solving this taks :)
★ 0 3y agoExplain → -
HiddenDesktop ⑂
HVNC for Cobalt Strike
★ 0 3y agoExplain → -
Nimbo-C2 ⑂
Nimbo-C2 is yet another (simple and lightweight) C2 framework
★ 0 3y agoExplain → -
PowerShell-Obfuscation-Bible ⑂
A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository are the result of personal research, including reading materials online and conducting trial-and-error attempts in labs and pentests.
★ 0 3y agoExplain → -
MalDoc-Embedded-EXE-Bin- ⑂
This is a technique one can use for their MalDoc.
★ 0 4y agoExplain → -
PrivKit ⑂
PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.
★ 0 3y agoExplain → -
Codecepticon ⑂
.NET/PowerShell/VBA Offensive Security Obfuscator
★ 0 3y agoExplain → -
ThreadlessInject-BOF ⑂
BOF implementation of @_EthicalChaos_'s ThreadlessInject project. A novel process injection technique with no thread creation, released at BSides Cymru 2023.
★ 0 3y agoExplain → -
Havoc ⑂
The Havoc Framework.
★ 0 3y agoExplain → -
Modules ⑂
Modules used by the Havoc Framework
★ 0 3y agoExplain → -
Talon ⑂
(Demo) 3rd party agent for Havoc
★ 0 3y agoExplain → -
PyHmmm ⑂
No description.
★ 0 3y agoExplain → -
havoc-py ⑂
Havoc python api
★ 0 3y agoExplain → -
SharpAgent ⑂
C# havoc implant
★ 0 3y agoExplain → -
ServerlessRedirector ⑂
Serverless Redirector in various cloud vendor for red team
★ 0 3y agoExplain → -
Ekko ⑂
Sleep Obfuscation
★ 0 3y agoExplain → -
ShellcodeTemplate ⑂
An easily modifiable shellcode template for Windows x64/x86
★ 0 3y agoExplain → -
KaynStrike ⑂
UDRL for CS
★ 0 4y agoExplain → -
KaynLdr ⑂
KaynLdr is a Reflective Loader written in C/ASM
★ 0 4y agoExplain → -
Unwinder ⑂
Another approach to thread stack spoofing.
★ 0 3y agoExplain → -
CoffeeLdr ⑂
Beacon Object File Loader
★ 0 3y agoExplain → -
titan ⑂
Titan: A generic user defined reflective DLL for Cobalt Strike
★ 0 3y agoExplain → -
c2-terraform ⑂
C2 deployment with Terraform
★ 0 4y agoExplain → -
ordliste ⑂
liste over norske ord og navn
★ 0 14y agoExplain → -
SandboxDefender ⑂
C# code to Sandbox Defender (and most probably other AV/EDRs).
★ 0 4y agoExplain → -
TokenStomp ⑂
C# implementation of the token privilege removal flaw discovered by @GabrielLandau/Elastic
★ 0 4y agoExplain → -
EvilSelenium ⑂
EvilSelenium is a tool that weaponizes Selenium to attack Chrome.
★ 0 4y agoExplain → -
NimPackt-v1 ⑂
Nim-based assembly packer and shellcode loader for opsec & profit
★ 0 4y agoExplain → -
VeraCryptThief ⑂
Extracting clear-text passwords from VeraCrypt.exe using API hooking
★ 0 4y agoExplain → -
ParallelNimcalls ⑂
Nim version of MDSec's Parallel Syscall PoC
★ 0 4y agoExplain → -
SuperSneakyExec ⑂
Loading and executing shellcode in C# without PInvoke.
★ 0 4y agoExplain → -
Azure-App-Tools ⑂
Collection of tools to use with Azure Applications
★ 0 4y agoExplain → -
CaddyStager ⑂
No description.
★ 0 4y agoExplain → -
inject-assembly ⑂
Execute .NET in an Existing Process
★ 0 4y agoExplain → -
bloodyAD ⑂
BloodyAD is an Active Directory Privilege Escalation Framework
★ 0 4y agoExplain → -
InstallerFileTakeOver ⑂
No description.
★ 0 4y agoExplain → -
WinBoost ⑂
Execute Mimikatz with different technique
★ 0 4y agoExplain → -
ProcessInjection ⑂
No description.
★ 0 6y agoExplain → -
ShellcodeFluctuation ⑂
An in-memory evasion technique fluctuating shellcode memory protection between RW & RX and encrypting/decrypting contents
★ 0 4y agoExplain → -
aad-sso-enum-brute-spray ⑂
POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln
★ 0 4y agoExplain → -
owncraft ⑂
offensive notes & resources
★ 0 4y agoExplain → -
SharpBeacon ⑂
CobaltStrike Beacon written in .Net 4 用.net重写了stager及Beacon,其中包括正常上线、文件管理、进程管理、令牌管理、结合SysCall进行注入、原生端口转发、关ETW等一系列功能
★ 0 4y agoExplain → -
SigFlip ⑂
SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
★ 0 5y agoExplain → -
Experienced-Pentester-OSEP ⑂
No description.
★ 0 5y agoExplain → -
ScallOps-Recipes ⑂
No description.
★ 0 5y agoExplain → -
ScallOps ⑂
No description.
★ 0 5y agoExplain → -
msspray ⑂
Password attacks and MFA validation against various endpoints in Azure and Office 365
★ 0 5y agoExplain → -
SourcePoint ⑂
SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
★ 0 5y agoExplain → -
TradecraftDevelopment-Fundamentals ⑂
Tradecraft Development Fundamentals
★ 0 5y agoExplain → -
Rubeus ⑂
Trying to tame the three-headed dog.
★ 0 5y agoExplain → -
jarm_randomizer ⑂
This tool was open sourced as part of JARM Randomizer: Evading JARM Fingerprinting for HiTB Amsterdam 2021.
★ 0 5y agoExplain → -
targetedKerberoast ⑂
Kerberoast with ACL abuse capabilities
★ 0 5y agoExplain → -
Offensive-VBA-and-XLS-Entanglement ⑂
No description.
★ 0 5y agoExplain → -
inceptor ⑂
Template-Driven AV/EDR Evasion Framework
★ 0 5y agoExplain → -
cs2webconfig ⑂
Convert Cobalt Strike profiles to IIS web.config files
★ 0 5y agoExplain → -
O.MG_Cable-Firmware ⑂
No description.
★ 0 5y agoExplain → -
AzureC2Relay ⑂
AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.
★ 0 5y agoExplain → -
SharpTransactedLoad ⑂
Load .net assemblies from memory while having them appear to be loaded from an on-disk location.
★ 0 5y agoExplain → -
UCantSeeM3 ⑂
Hiding your process in ProcessHacker,Task Manager,etc by patching NtQuerySystemInformation
★ 0 5y agoExplain → -
ADCSPwn ⑂
A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.
★ 0 5y agoExplain → -
scarecrow_wrapper ⑂
No description.
★ 0 5y agoExplain → -
PortBender ⑂
TCP Port Redirection Utility
★ 0 5y agoExplain → -
PKINITtools ⑂
Tools for Kerberos PKINIT and relaying to AD CS
★ 0 5y agoExplain → -
CredPhish ⑂
CredPhish is a PowerShell script designed to invoke legitimate credential prompts and exfiltrate passwords over DNS.
★ 0 5y agoExplain → -
BadAssMacros ⑂
BadAssMacros - C# based automated Malicous Macro Generator.
★ 0 5y agoExplain → -
PowerSploit ⑂
PowerSploit - A PowerShell Post-Exploitation Framework
★ 0 5y agoExplain → -
NET-Obfuscate ⑂
Obfuscate ECMA CIL (.NET IL) assemblies to evade Windows Defender AMSI
★ 0 5y agoExplain → -
ThirdEye ⑂
Weaponizing CLRvoyance for Post-Ex .NET Execution
★ 0 5y agoExplain → -
ScareCrow-CobaltStrike ⑂
Cobalt Strike script for ScareCrow payloads
★ 0 5y agoExplain → -
PrintNightmare ⑂
No description.
★ 0 5y agoExplain → -
PEzor ⑂
Open-Source PE Packer
★ 0 5y agoExplain → -
TokenTactics ⑂
Azure JWT Token Manipulation Toolset
★ 0 5y agoExplain → -
RedTeamCCode ⑂
Red Team C code repo
★ 0 5y agoExplain → -
CVE-2021-1675 ⑂
Impacket implementation of CVE-2021-1675
★ 0 5y agoExplain → -
AppProxyC2 ⑂
No description.
★ 0 5y agoExplain → -
RosFuscator ⑂
YouTube/Livestream project for obfuscating C# source code using Roslyn
★ 0 5y agoExplain → -
BetterXencrypt ⑂
A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs.
★ 0 5y agoExplain → -
slae32 ⑂
Assignments for the SecurityTube Linux Assembly Expert Certification (SLAE)
★ 0 7y agoExplain → -
cook ⑂
A customizable wordlist and password generator.
★ 0 5y agoExplain → -
ScareCrow ⑂
ScareCrow - Payload creation framework designed around EDR bypass.
★ 0 5y agoExplain → -
darkdump ⑂
Search The Deep Web Straight From Your Terminal
★ 0 5y agoExplain → -
OffensivePipeline ⑂
OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.
★ 0 5y agoExplain → -
random_c2_profile ⑂
Cobalt Strike random C2 Profile generator
★ 0 5y agoExplain → -
build_a_phish ⑂
Ansible playbook to deploy a phishing engagement
★ 0 5y agoExplain → -
cobalt-arsenal ⑂
My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+
★ 0 5y agoExplain → -
SharpWebServer ⑂
Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality
★ 0 5y agoExplain → -
bloodhound-quickwin ⑂
Simple script to extract useful informations from the combo BloodHound + Neo4j
Python ★ 0 5y agoExplain → -
updog ⑂
Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth.
★ 0 5y agoExplain → -
pwncat ⑂
Fancy reverse and bind shell handler
★ 0 5y agoExplain → -
SocksProxyServer-Plugin ⑂
Socks Proxy Server Plugin for Invoke-SocksProxy
★ 0 5y agoExplain → -
Aggressor-VYSEC ⑂
No description.
★ 0 7y agoExplain → -
AggressorScripts ⑂
Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources
★ 0 5y agoExplain → -
Chameleon ⑂
Chameleon: A tool for evading Proxy categorisation
★ 0 6y agoExplain → -
Proxylogon-exploit ⑂
proxylogon exploit - CVE-2021-26857
★ 0 5y agoExplain → -
gscript ⑂
framework to rapidly implement custom droppers for all three major operating systems
★ 0 6y agoExplain → -
SpookFlare ⑂
Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.
★ 0 7y agoExplain → -
OSEP-Code-Snippets ⑂
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
★ 0 5y agoExplain → -
SIGRed_RCE_PoC ⑂
No description.
★ 0 5y agoExplain → -
scanning ⑂
No description.
★ 0 5y agoExplain → -
SharpSphere ⑂
.NET Project for Attacking vCenter
★ 0 5y agoExplain → -
SharpLAPS ⑂
Retrieve LAPS password from the LDAP
★ 0 5y agoExplain → -
defcon27_csharp_workshop ⑂
Writing custom backdoor payloads with C# - Defcon 27 Workshop
★ 0 7y agoExplain → -
GRAT2 ⑂
We developed GRAT2 Command & Control (C2) project for learning purpose.
★ 0 5y agoExplain → -
BOFs ⑂
Collection of Beacon Object Files
★ 0 5y agoExplain → -
spoonmap ⑂
No description.
★ 0 5y agoExplain → -
DKMC ⑂
DKMC - Dont kill my cat - Malicious payload evasion tool
★ 0 6y agoExplain → -
OffensiveNim ⑂
My experiments in weaponizing Nim (https://nim-lang.org/)
★ 0 5y agoExplain → -
c-sharp-memory-injection ⑂
A set of scripts that demonstrate how to perform memory injection in C#
★ 0 8y agoExplain → -
Appx_Blog ⑂
No description.
★ 0 5y agoExplain → -
extps-cobalt-strike-bof ⑂
Extended Process List (Search functionality)
★ 0 5y agoExplain → -
RdpThief ⑂
Extracting Clear Text Passwords from mstsc.exe using API Hooking.
★ 0 6y agoExplain → -
Invoke-Sharpcradle ⑂
Load C# Code straight to memory
★ 0 6y agoExplain → -
SharpLoginPrompt ⑂
No description.
★ 0 5y agoExplain → -
CovenantTasks ⑂
Source for tasks I have used with Covenant
★ 0 6y agoExplain → -
CSSG ⑂
Cobalt Strike Shellcode Generator
★ 0 5y agoExplain → -
MaliciousClickOnceMSBuild ⑂
Basic C# Project that will take an MSBuild payload and run it with MSBuild via ClickOnce.
★ 0 5y agoExplain → -
CobaltStrike-BOF ⑂
Collection of beacon BOF written to learn windows and cobaltstrike
★ 0 5y agoExplain → -
PlumHound ⑂
Bloodhound for Blue and Purple Teams
★ 0 6y agoExplain → -
GadgetToJScript ⑂
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
★ 0 5y agoExplain → -
Chimera ⑂
Chimera is a (shiny and very hack-ish) PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
★ 0 5y agoExplain → -
TruffleSnout ⑂
Iterative AD discovery toolkit for offensive operations
★ 0 6y agoExplain → -
bof-NetworkServiceEscalate ⑂
Abuses the Shared Logon Session ID Issue (Described [here](https://www.tiraniddo.dev/2020/04/sharing-logon-session-little-too-much.html) by the awesome James Forshaw) To Achieve System From NetworkService. Can be used as a "getsystem" as well
★ 0 6y agoExplain → -
DAFT ⑂
DAFT: Database Audit Framework & Toolkit
★ 0 7y agoExplain → -
CS-Situational-Awareness-BOF ⑂
No description.
★ 0 5y agoExplain → -
domainhunter ⑂
Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
★ 0 6y agoExplain → -
malleable-c2 ⑂
Cobalt Strike Malleable C2 Design and Reference Guide
★ 0 6y agoExplain → -
Mythic ⑂
A collaborative, multi-platform, red teaming framework
★ 0 5y agoExplain → -
DLLsForHackers ⑂
Dll that can be used for side loading and other attack vector.
★ 0 5y agoExplain → -
nccfsas ⑂
Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.
★ 0 5y agoExplain → -
cloudsploit ⑂
Cloud Security Posture Management (CSPM)
★ 0 5y agoExplain → -
Zolom ⑂
C# Executable with embedded Python that can be used reflectively to run python code on systems without Python installed
★ 0 6y agoExplain → -
zer0dump ⑂
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
★ 0 5y agoExplain → -
EvtMute ⑂
Apply a filter to the events being reported by windows event logging
★ 0 5y agoExplain → -
GhostBuild ⑂
GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects
★ 0 6y agoExplain → -
BloodHoundQueries ⑂
No description.
★ 0 6y agoExplain → -
SharpMove ⑂
.NET Project for performing Authenticated Remote Execution
★ 0 6y agoExplain → -
SharpStay ⑂
.NET project for installing Persistence
★ 0 6y agoExplain → -
PowerView3-Aggressor ⑂
Cobalt Strike Aggressor script menu for Powerview/SharpView
★ 0 7y agoExplain → -
ProcessInjection-1 ⑂
This program is designed to demonstrate various process injection techniques
★ 0 5y agoExplain → -
SharpAppLocker ⑂
C# port of the Get-AppLockerPolicy PS cmdlet
★ 0 6y agoExplain → -
impacket ⑂
Temporary Impacket Fork for Contributing and Sharing Our Knowledge about Windows
★ 0 6y agoExplain → -
Stormspotter ⑂
Azure Red Team tool for graphing Azure and Azure Active Directory objects
★ 0 6y agoExplain → -
VBA-RunPE ⑂
A VBA implementation of the RunPE technique or how to bypass application whitelisting.
★ 0 6y agoExplain → -
BetterSafetyKatz ⑂
BetterSafetyKatz
★ 0 6y agoExplain → -
APT06202001 ⑂
Applied Purple Teaming - Infrastructure, Threat Optics, and Continious Improvement - June 6, 2020
★ 0 6y agoExplain → -
AES-PowerShellCode ⑂
Standalone version of my AES Powershell payload for Cobalt Strike.
★ 0 6y agoExplain → -
PoC-in-GitHub ⑂
📡PoC auto collect from GitHub.
★ 0 6y agoExplain → -
petaqc2 ⑂
Petaq - Purple Team Command & Control Server
★ 0 6y agoExplain → -
SharpSploit ⑂
SharpSploit is a .NET post-exploitation library written in C#
★ 0 6y agoExplain → -
BlackBird ⑂
Subdomain Enumeration and Scanner
★ 0 6y agoExplain → -
lazyrecon ⑂
This script is intended to automate your reconnaissance process in an organized fashion
★ 0 6y agoExplain → -
redteam ⑂
Red Team Scripts by d0nkeys (ex SnadoTeam)
★ 0 6y agoExplain → -
SharpFiles ⑂
No description.
★ 0 7y agoExplain → -
breaking-and-pwning-apps-and-servers-aws-azure-training ⑂
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
★ 0 6y agoExplain → -
Ghost-In-The-Logs ⑂
Evade sysmon and windows event logging
★ 0 6y agoExplain → -
spoofing-office-macro ⑂
:fish: PoC of a VBA macro spawning a process with a spoofed parent and command line.
★ 0 6y agoExplain → -
Fudge ⑂
Hiding implants in HTML files
★ 0 6y agoExplain → -
UltimateAppLockerByPassList ⑂
The goal of this repository is to document the most common techniques to bypass AppLocker.
★ 0 6y agoExplain → -
CVE-2020-0796 ⑂
CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
★ 0 6y agoExplain → -
FullPowers ⑂
Recover the default privilege set of a LOCAL/NETWORK SERVICE account
★ 0 6y agoExplain → -
NoAmci ⑂
Using DInvoke to patch AMSI.dll in order to bypass AMSI detections triggered when loading .NET tradecraft via Assembly.Load().
★ 0 6y agoExplain → -
my-arsenal-of-aws-security-tools ⑂
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
★ 0 6y agoExplain → -
evilginx2 ⑂
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
★ 0 6y agoExplain → -
CarbonCopy ⑂
A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
★ 0 7y agoExplain → -
lterm ⑂
lterm is a small script built to install a bash hook for full terminal logging.
★ 0 9y agoExplain → -
DecryptTeamViewer ⑂
Enumerate and decrypt TeamViewer settings from registry
★ 0 6y agoExplain → -
DaaC2 ⑂
Discord as a C2
★ 0 6y agoExplain → -
PowerStrip ⑂
No description.
★ 0 6y agoExplain → -
Empire ⑂
Empire is a PowerShell and Python post-exploitation agent.
★ 0 6y agoExplain → -
cve-2019-19781 ⑂
This is a tool published for the Citrix ADC (NetScaler) vulnerability. We are only disclosing this due to others publishing the exploit code first.
★ 0 6y agoExplain → -
plaintext ⑂
No description.
★ 0 6y agoExplain → -
Salsa-tools ⑂
Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched
★ 0 6y agoExplain → -
Red-Team-Infrastructure-Wiki ⑂
Wiki to collect Red Team infrastructure hardening resources
★ 0 7y agoExplain → -
Covenant ⑂
Covenant is a collaborative .NET C2 framework for red teamers.
★ 0 6y agoExplain → -
Bloodhound-Custom-Queries ⑂
Custom Query list for the Bloodhound GUI based off my cheatsheet
★ 0 6y agoExplain → -
rubeus2ccache ⑂
Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.
★ 0 6y agoExplain →
No repos match these filters.