1-day longest streak
-
EVTX-ATTACK-SAMPLES ★ PINNED
Windows Events Attack Samples
HTML ★ 2.6k 3y agoExplain → -
Slides ★ PINNED
Misc Threat Hunting Resources
★ 377 3y agoExplain → -
PCAP-ATTACK ★ PINNED
PCAP Samples for Different Post Exploitation Techniques
★ 375 5y agoExplain → -
YaraHunts ★ PINNED
Random hunting ordiented yara rules
YARA ★ 96 3y agoExplain → -
macOS-ATTACK-DATASET ★ PINNED
JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.
★ 160 4y agoExplain → -
EDRUnChoker
EDRUnChoker - fileless WMI defense that removes EDRChoker QoS throttling policies
PowerShell ★ 44 1mo agoExplain → -
gluegate
Memory API proxy via signed mozglue.dll
C ★ 40 27d agoExplain → -
injection-1 ⑂
Windows process injection methods
C ★ 21 7y agoExplain → -
mail-security-tester ⑂
A testing framework for mail security and filtering solutions.
Python ★ 8 7y agoExplain → -
shad0w ⑂
A post exploitation framework designed to operate covertly on heavily monitored enviroments
★ 7 6y agoExplain → -
APT_Digital_Weapon ⑂
Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.
★ 5 6y agoExplain → -
malware-1 ⑂
Malware source code samples leaked online uploaded to GitHub for those who want to analyze the code.
★ 4 9y agoExplain → -
evtx2es ⑂
Import Windows Eventlogs(.evtx) to ElasticSearch.
★ 4 6y agoExplain → -
APT_CyberCriminal_Campagin_Collections ⑂
APT & CyberCriminal Campaign Collection
JavaScript ★ 3 7y agoExplain → -
PythonForWindows ⑂
A codebase aimed to make interaction with Windows and native execution easier
★ 3 6y agoExplain → -
MalConfScan ⑂
Volatility plugin for extracts configuration data of known malware
Python ★ 3 7y agoExplain → -
WindowsDefenderATP-Hunting-Queries ⑂
Sample queries for Advanced hunting in Microsoft Defender ATP
★ 3 6y agoExplain → -
Adama ⑂
Searches For Threat Hunting and Security Analytics
★ 3 6y agoExplain → -
malware-ioc ⑂
Indicators of Compromises (IOC) of our various investigations
★ 2 6y agoExplain → -
Win10 ⑂
Win 10 related research
★ 2 7y agoExplain → -
Windows-Kernel-Explorer ⑂
A free but powerful Windows kernel research tool.
★ 2 6y agoExplain → -
UACME ⑂
Defeating Windows User Account Control
C ★ 2 7y agoExplain → -
APT_REPORT ⑂
Interesting apt report collection and some special ioc express
Python ★ 2 7y agoExplain → -
sysmonx ⑂
SysmonX - An Augmented Drop-In Replacement of Sysmon
C++ ★ 2 7y agoExplain → -
rules ⑂
Repository of yara rules
★ 2 6y agoExplain → -
auditd ⑂
Best Practice Auditd Configuration
★ 2 6y agoExplain → -
OffensiveVBA ⑂
This repo covers some code execution and AV Evasion methods for Macros in Office documents
VBA ★ 2 4y agoExplain → -
detection-rules ⑂
Rules for Elastic Security's detection engine
★ 1 2y agoExplain → -
osq-ext-bin ⑂
Extension to osquery windows that enhances it with real-time telemetry, log monitoring and other endpoint data collection
★ 1 6y agoExplain → -
ExchangeLogCollector ⑂
Exchange Log Collection Script
★ 1 6y agoExplain → -
PowerMemory ⑂
Exploit the credentials present in files and memory
★ 1 9y agoExplain → -
OneOffs ⑂
Small random scripts for various things I find myself needing to repeat/automate
★ 1 7y agoExplain → -
unicorn ⑂
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
★ 1 7y agoExplain → -
InfinityHook ⑂
Hook system calls, context switches, page faults and more.
★ 1 7y agoExplain → -
PowerSploit ⑂
PowerSploit - A PowerShell Post-Exploitation Framework
★ 1 7y agoExplain → -
PeFixup ⑂
PE File Blessing - To continue or not to continue
★ 1 6y agoExplain → -
sandbox-attacksurface-analysis-tools ⑂
Set of tools to analyze and attack Windows sandboxes.
★ 1 6y agoExplain → -
AsyncRAT-C-Sharp ⑂
Open-Source Remote Administration Tool For Windows C# (RAT)
★ 1 6y agoExplain → -
VBA-RunPE ⑂
A VBA implementation of the RunPE technique or how to bypass application whitelisting.
★ 1 6y agoExplain → -
Windows-classic-samples ⑂
This repo contains samples that demonstrate the API used in Windows classic desktop applications.
★ 1 5y agoExplain → -
HyperDbg ⑂
The Source Code of HyperDbg Debugger 🐞
★ 1 5y agoExplain → -
webshell ⑂
This is a webshell open source project
★ 1 6y agoExplain → -
ioc-scanner-CVE-2019-19781 ⑂
Indicator of Compromise Scanner for CVE-2019-19781
★ 1 6y agoExplain → -
HastySeries ⑂
ObscurityLabs RedTeam C# Toolkit
★ 1 6y agoExplain → -
LinEnum ⑂
Scripted Local Linux Enumeration & Privilege Escalation Checks
★ 1 6y agoExplain → -
injectAllTheThings ⑂
Seven different DLL injection techniques in one single project.
★ 1 6y agoExplain → -
sigma ⑂
Generic Signature Format for SIEM Systems
Python ★ 1 6y agoExplain → -
Revoke-Obfuscation ⑂
PowerShell Obfuscation Detection Framework
★ 1 6y agoExplain → -
eqllib ⑂
No description.
Python ★ 1 6y agoExplain → -
Rubeus ⑂
Trying to tame the three-headed dog.
★ 1 7y agoExplain → -
defcon_27_windbg_workshop ⑂
DEFCON 27 workshop - Modern Debugging with WinDbg Preview
★ 1 7y agoExplain → -
Sharp-SMBExec ⑂
SMBExec C# module
★ 1 7y agoExplain → -
injection ⑂
No description.
C++ ★ 1 7y agoExplain → -
office-exploit-case-study ⑂
No description.
Rich Text Format ★ 1 7y agoExplain → -
protections-artifacts ⑂
Elastic Security detection content for Endpoint
★ 0 4y agoExplain → -
signed-loaders ⑂
signed-loaders documents Windows executables that can be used for side-loading DLLs.
★ 0 7y agoExplain → -
CVE-2020-0796-PoC ⑂
PoC for triggering buffer overflow via CVE-2020-0796
★ 0 6y agoExplain → -
WindowsProtocolTestSuites ⑂
Windows Protocol Test Suites provide interoperability testing against an implementation of the Windows open specifications.
★ 0 6y agoExplain → -
ysoserial.net ⑂
Deserialization payload generator for a variety of .NET formatters
★ 0 6y agoExplain → -
CVE-2020-0688_EXP ⑂
CVE-2020-0688_EXP Auto trigger payload & encrypt method
★ 0 6y agoExplain → -
mbc-markdown ⑂
MBC content in markdown
★ 0 6y agoExplain → -
fastir_artifacts ⑂
Live forensic artifacts collector
★ 0 6y agoExplain → -
azorult ⑂
Leaked AzoRult Panel
★ 0 7y agoExplain → -
Empire ⑂
Empire is a PowerShell and Python post-exploitation agent.
★ 0 6y agoExplain → -
webshellkill-cli ⑂
Using Windows Hook to make a CLI WebShellKill
★ 0 7y agoExplain → -
ConventionEngine ⑂
ConventionEngine - A Yara Rulepack for PDB Path Hunting
★ 0 6y agoExplain → -
BasicInputOutput ⑂
collateral from http://basicinputoutput.com
★ 0 7y agoExplain → -
RegRipper2.8 ⑂
RegRipper version 2.8
★ 0 7y agoExplain → -
core-win32 ⑂
RCS Agent for Windows (32bit)
★ 0 11y agoExplain → -
SharpSploit ⑂
SharpSploit is a .NET post-exploitation library written in C#
★ 0 6y agoExplain → -
pinjectra ⑂
Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)
C++ ★ 0 7y agoExplain →
No repos match these filters.
More creators on gitmyhub
programthink xiaolai brunosimon douglascrockford standardgalactic