88-day longest streak
Intro: Andy has been consulting in offensive security for over a decade, focusing on red teaming and simulated attacks with a side of threat intelligence and purple teaming. Leading engagements…
Intro:
Andy has been consulting in offensive security for over a decade, focusing on red teaming and simulated attacks with a side of threat intelligence and purple teaming. Leading engagements of varying sizes and lengths, helping grow teams and encouraging risk-driven understanding.
Creator of ZephrSec LMS and ZephrSec.

Projects:
- pR1 - serverless URL shortener built on Cloudflare Workers
- LCA - Local Code Agent, a similar idea to Claude Code but for lmstudio usage locally instead, useful for tool development
- pyLDAPGui - Python based GUI LDAP browser app thing
- GoClipC2 - Clipboard for C2 on Windows
- ChunkyIngress - A tool for ingressing large blocks of text in limited environments
- DynamicMSBuilder
- RepoMan - Dynamic Git Commits using LLMs
- HelloJackHunter - Dynamic DLL Hijacking and Exports
- CredMaster - I actively help with Credmaster, having written several modules and helped overhaul Credmaster 2.0.
- AzureAttackKit
- AutoHoneyPoC
- SandboxSpy
- BurpFeed
- PrintNightmare Detection Info
- SlinkyCat
- Offensive Sysadmin Suite
- HelpColor Aggressor Script - I try to keep Outflank's aggressor up to date with new cool BOFs and things :)
- Malleable-C2 - I actively contribute to Malleable C2 at each release, explaining the different options to help you make better C2 profiles within Cobalt Strike.
- OmniProx - An IP rotation tool similar to how FireProx operates but for different providers
Pages
Blog:
I post most of my research and other interesting tutorials on my blog; I also have a photos blog where I share pics I take; ZephrSnapsCourse:
I have written a course aimed at professionals wanting to learn more about red teaming, it focuses on red teaming from the perspective of not depending upon C2 and traditional malware but also teaches the background to red teaming that a lot of courses miss. https://lms.zsec.redBook:
For those that don't know Andy, he is a firm believer in passing knowledge on and supporting the infosec community he does this by providing tutorials on his blog running his local DEF CON Chapter & has also published two books Breaking into Information Security and LTR102. He also helps out at DEF CON as a SOC Goon (Red Shirt) too each year (since DC24), assisting the SOC with operations and people flow.
Talks:
All my talks can be found here: https://github.com/ZephrFish/talks
Bug Bounty:
Badges
Andy has been in the IT security industry for just over 15 years, a decade of which has been dedicated to security and offensive operations. Currently holds CREST's Certified Red Team Specialist (CCRTS) and he has previously held CREST’s CCT Infrastructure certification, which is highly sought-after, and CHECK Team Leader status. In addition to his years in the industry, he holds several other certifications and accolades, including CCRTS, CRTO, OSCP, and OSWP.-
BurpFeed ★ PINNED
Hacked together script for feeding urls into Burp's Sitemap
Python ★ 97 7mo agoExplain → -
BugBountyTemplates ★ PINNED
A collection of templates for bug bounty reporting
★ 492 7mo agoExplain → -
Wordlists ★ PINNED ▣
Various Payload wordlists
★ 244 1y agoExplain → -
Bloodhound-CustomQueries ★ PINNED
Custom Queries - Brought Up to BH4.1 syntax
★ 284 7mo agoExplain → -
RandomScripts ★ PINNED
Random Shell Scripts and other ideas I have along the way
PowerShell ★ 73 6mo agoExplain → -
LOLADCS ★ PINNED
PowerShell implementation for AD CS
PowerShell ★ 157 4mo agoExplain → -
GoogD0rker ▣
Note: Going through a full re-write of the tooling so the current versions in the repo do not work!
Python ★ 418 6y agoExplain → -
OmniProx
IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare
Python ★ 293 7mo agoExplain → -
DockerAttack ▣
Various Tools and Docker Images
Dockerfile ★ 281 1y agoExplain → -
CVE-2020-1350_HoneyPoC ▣
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Windows Server 2019.
PowerShell ★ 279 5y agoExplain → -
pyLDAPGui
Python based GUI for browsing LDAP
Python ★ 183 7mo agoExplain → -
static-tools ▣
Static compiled binaries + scripts ready to use on systems
Lua ★ 153 1y agoExplain → -
QoL-BOFs
Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning
C ★ 140 7mo agoExplain → -
WindowsHardeningScript
Some settings stolen from multiple scripts @ZephrFish
Batchfile ★ 137 7mo agoExplain → -
LOLSearches
Living off the land searches for explorer and sharepoint
★ 102 7mo agoExplain → -
harness-kit
A template for building your own AI/LLM harness
★ 83 5d agoExplain → -
AzureAttackKit
Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information
PowerShell ★ 79 7mo agoExplain → -
XSSPayloads ▣
Cross Site Scripting Payloads -- Variations
★ 72 1y agoExplain → -
ludus-defender-lab
MDE/MDI Defender setup for Ludus
PowerShell ★ 61 4mo agoExplain → -
F5-CVE-2022-1388-Exploit
Exploit and Check Script for CVE 2022-1388
Python ★ 59 7mo agoExplain → -
GoClipC2
Clipboard for Command and Control between VDI, RDP and Others on Windows
Go ★ 53 7mo agoExplain → -
Stompy
Timestomp Tool to flatten MAC times with a specific timestamp
C# ★ 49 7mo agoExplain → -
AttackDeploy ▣
Scripts for Deploying new server
Shell ★ 49 1y agoExplain → -
CVE-2021-22893_HoneyPoC2 ▣
DO NOT RUN THIS.
Shell ★ 47 4y agoExplain → -
ADFSDump-PS
PowerShell Implementation of ADFSDump to assist with GoldenSAML
PowerShell ★ 44 7mo agoExplain → -
GoogD0rk ▣
No description.
Python ★ 43 1y agoExplain → -
DynamicMSBuilder
A Dynamic MSBuild task to help with minor obfuscation of C# Binaries to evade static signatures on each compilation
C# ★ 38 7mo agoExplain → -
AutoHoneyPoC
AutoPoC Generator HoneyPoC
Python ★ 36 7mo agoExplain → -
TokenBurn
No description.
HTML ★ 34 3mo agoExplain → -
CVE-2023-20198-Checker
CVE-2023-20198 & 0Day Implant Scanner
Python ★ 33 7mo agoExplain → -
CVE-2024-4577-PHP-RCE
PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template
Go ★ 32 7mo agoExplain → -
SandboxSpy
Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them back in a Base32 string over HTTP to an endpoint.
Go ★ 31 7mo agoExplain → -
HelloJackHunter
Research into WinSxS binaries and finding hijackable paths
C# ★ 31 7mo agoExplain → -
Exch-CVE-2021-26855 ▣
CVE-2021-26855: PoC (Not a HoneyPoC for once!)
Python ★ 30 1y agoExplain → -
wp2shell-scanner
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
Python ★ 26 6d agoExplain → -
ChunkyIngress
Leverages B64 chunks to split files and save to clipboard
PowerShell ★ 26 7mo agoExplain → -
CVE-2020-16898 ▣
HoneyPoC 2.0: Proof-of-Concept (PoC) script to exploit IPv6 (CVE-2020-16898).
★ 22 1y agoExplain → -
Blog_Backup ▣
A repository with various tutorials on how to do things in Pentesting, setup environments and other things
★ 21 1y agoExplain → -
RepoMan
Repo hacks
Python ★ 21 7mo agoExplain → -
CopyFail-CVE-2026-31431
No description.
Python ★ 20 2mo agoExplain → -
CVE-2023-34362 ⑂
CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
Ruby ★ 19 2y agoExplain → -
CVE-2025-53770-Scanner
ToolShell scanner - CVE-2025-53770 and detection information
Python ★ 18 7mo agoExplain → -
CVE-2021-41773-PoC
No description.
Python ★ 17 7mo agoExplain → -
SCCMSiteCodeHunter
No description.
C# ★ 16 7mo agoExplain → -
PotUtils
No description.
Go ★ 16 7mo agoExplain → -
NessusPreFlight ▣
Nessus Preflight(NPF) Check for local and remote systems. Essentially sets three registry keys and restarts a service to allow nessus to scan a machine
PowerShell ★ 16 1y agoExplain → -
edr-checker ⑂
Gets the name of all currently running process then checks them against a list of known defensive products such as AV's, EDR's and logging tools.
PowerShell ★ 15 3y agoExplain → -
GhidraMacOS
Ghidra launcher for MacOS as a .app file
Shell ★ 14 7mo agoExplain → -
LOLPROX
No description.
HTML ★ 13 5mo agoExplain → -
MoveIT-WebShellCheck
No description.
Python ★ 12 7mo agoExplain → -
PurpleTeamWorkshop-LabManual ▣
Purple Team Workshop by @jorgeorchilles
★ 12 1y agoExplain → -
blind
A BOF for patching AMSI, ETW and NtTraceEvent aka Sysmon using Trampolines
C ★ 11 2mo agoExplain → -
Lepus ⑂
Subdomain finder
Python ★ 11 1y agoExplain → -
Red-Teaming-Toolkit ⑂
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
★ 11 4y agoExplain → -
XSS ▣
A collection of XSS Attack vectors
★ 10 1y agoExplain → -
NOPe ⑂
NOPe - Testing some alternate NOP opcodes
Python ★ 9 6mo agoExplain → -
xss-proxy
BeEF-inspired XSS proxy service
HTML ★ 9 7mo agoExplain → -
Autopeeper ▣
Automated Screenshot Tool
Python ★ 9 1y agoExplain → -
MediaCenterSetup ▣
A setup script for Plex, Sonarr, Radarr & Jackett
Shell ★ 8 1y agoExplain → -
ZephrFish
About ZephrFish | ZephrSec
★ 7 4h agoExplain → -
bugbountydork ⑂
Bug Bounty Dork
Python ★ 7 9y agoExplain → -
NotProxyShellScanner
Python implementation for NotProxyShell aka CVE-2022-40140 & CVE-2022-41082
Python ★ 7 4mo agoExplain → -
CommitStomping-Info
Commit Stomping is a technique in which Git commit timestamps are manipulated to obscure the true timing of changes.
★ 7 7mo agoExplain → -
OffensiveSysAdmin ⑂
A collection of tools Neil and Andy have been working on released in one place and interlinked with previous tools
★ 7 3y agoExplain → -
LTR101 ▣
Repository for Breaking into Information Security: Learning the Ropes 101 (https://leanpub.com/ltr101-breaking-into-infosec)
★ 7 1y agoExplain → -
SharpCMLoot
C# version of cmloot for SCCM Enumeration on Windows
C# ★ 6 4mo agoExplain → -
ProxyForge
An attempt at a Chrome Plugin that does IP Rotation using AWS API Gateways
JavaScript ★ 6 7mo agoExplain → -
LogsSteelcon
No description.
★ 6 7mo agoExplain → -
dns-parallel-prober ⑂
PoC for an adaptive parallelised DNS prober
Go ★ 6 7mo agoExplain → -
PS-Scripts ▣
Useful scripts for labs
PowerShell ★ 6 1y agoExplain → -
LegacyResearch ▣
No description.
Python ★ 6 1y agoExplain → -
OldGold
Sysadmin Tools
HTML ★ 5 7mo agoExplain → -
HeadlessBounties ▣
A shell script that bundles Eyewitness and Sublist3r to create a great fingerprinting tool
Shell ★ 5 1y agoExplain → -
Exploit-Street ⑂
Complete list of LPE exploits for Windows (starting from 2023)
★ 4 8mo agoExplain → -
Random-Yara-Rules ▣
A collection of yara rules I've gathered over the years :-)
YARA ★ 4 1y agoExplain → -
Exch-CVE-2021-26855_Priv
patched to work
Python ★ 4 7mo agoExplain → -
Mailgun-python ▣
Python Wrapper for sending email with mailgun
Python ★ 4 1y agoExplain → -
CSVInjectionPayloads ▣
A list of various ways of injecting payloads for CSV Injection
★ 4 1y agoExplain → -
LittleCorporal ⑂
LittleCorporal: A C# Automated Maldoc Generator
★ 4 5y agoExplain → -
rengine ⑂
reNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.
★ 4 5y agoExplain → -
MDReportServer
A tiny, zero-dependency web app for reviewing Markdown reports and their attachments, with one-click copy and a themed viewer.
Python ★ 3 3h agoExplain → -
WebSocketsAreFun
FAFO with WebSockets
PowerShell ★ 3 7mo agoExplain → -
SSH_Notify
Different Scripts for SSH hardening blog
Python ★ 3 7mo agoExplain → -
UnhookingPatch ⑂
Bypass EDR Hooks by patching NT API stub, and resolving SSNs and syscall instructions at runtime
C++ ★ 3 2y agoExplain → -
KeyTabExtract ⑂
Extracts Key Values from .keytab files
Python ★ 3 9mo agoExplain → -
DoNotRunMe
No description.
★ 3 7mo agoExplain → -
CVE-2021-22986_Check ▣
CVE-2021-22986 Checker Script in Python3
Python ★ 3 1y agoExplain → -
charlotte ⑂
c++ fully undetected shellcode launcher ;)
Python ★ 3 5y agoExplain → -
InlineExecute-Assembly ⑂
InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module
★ 3 5y agoExplain → -
Talks
A simple reference for all of my public talks
★ 2 10d agoExplain → -
HavocMacOS
No description.
Shell ★ 2 7mo agoExplain → -
pR1
No description.
JavaScript ★ 2 26d agoExplain → -
VSCVBED
Visual Studio Code Plugin that decodes VBE files on the fly
TypeScript ★ 2 4mo agoExplain → -
Sub2CDN
No description.
Python ★ 2 7mo agoExplain → -
zephrfish.github.io
zsec backup blog
★ 2 7mo agoExplain → -
ProxOptimise
No description.
Shell ★ 2 3mo agoExplain → -
ReverseRDPRCE
Fork from github.com/klinix5/ReverseRDP_RCE
C++ ★ 2 7mo agoExplain → -
ProxyGen
Deploy Wireguard to multiple cloud providers with TF and Python - 100% coded with Claude
Python ★ 2 7mo agoExplain → -
CVE-2024-3400-Canary
Have we not learnt from HoneyPoC?
Python ★ 2 7mo agoExplain → -
awesome-bof ⑂
🧠 The ultimate, community-curated resource for Beacon Object Files (BOFs) — tutorials, how-tos, deep dives, and reference materials.
★ 2 1y agoExplain → -
CVE-2025-64446 ⑂
A scanner for the FortiNet vulnerability CVE-2025-64446
★ 2 8mo agoExplain → -
csc_cypher ▣
Cyber Security Challenge Cipher Challenge
★ 2 1y agoExplain → -
Writeups ▣
Various write-ups from CTFs, fixes for things and others
★ 2 1y agoExplain → -
LearnTheRopes ▣
An outline as to how to get the basics nailed down before approaching information security as a career
★ 2 1y agoExplain → -
CTF-Solutions ▣
No description.
★ 2 1y agoExplain → -
Evilginx-Phishing-Infra-Setup ⑂
Evilginx Phishing Engagement Infrastructure Setup Guide
★ 2 2y agoExplain → -
ThreatIntelligenceConsumer ⑂
Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL privilege.
★ 1 6mo agoExplain → -
zephrsnaps.github.io
No description.
★ 1 7mo agoExplain → -
xfer
ingress tooling
★ 1 7mo agoExplain → -
VPNConnectScript
VPN Connection Menu Script, Created in Bash
Shell ★ 1 7mo agoExplain → -
SysmonConfigPusher2 ⑂
Sysmon Config Pusher - Modernized
C# ★ 1 28d agoExplain → -
pacman-contribution-graph ⑂
🟡👻 Turn your GitHub contribution graph into a Pac-Man SVG animation! Easy to integrate into your profile with GitHub Actions 🚀.
TypeScript ★ 1 26d agoExplain → -
exploitation-validator ⑂
A prompt-based pipeline for finding, validating, and proving vulnerabilities using LLM sub-agents.
★ 1 3mo agoExplain → -
Mac4SBQ
No description.
Shell ★ 1 2mo agoExplain → -
HomelabDockersAutomation
No description.
Python ★ 1 4mo agoExplain → -
ludus ⑂
[GITLAB MIRROR] Ludus is a system to build easy to use cyber environments for testing and development.
★ 1 4mo agoExplain → -
Mac-setup-automation
Setup and Automation for new Mac setup, zsh, brew, application setup and more
Shell ★ 1 7mo agoExplain → -
mp-lookup
Find your local MP in UK and Email them about OSA and Digital ID
JavaScript ★ 1 7mo agoExplain → -
ludus-sysmon
Sysmon Template for Ludus
★ 1 7mo agoExplain → -
LearningThings
No description.
★ 1 7mo agoExplain → -
EXEfromCER ⑂
PoC that downloads an executable from a public SSL certificate
★ 1 1y agoExplain → -
ysonet ⑂
Deserialization payload generator for a variety of .NET formatters
C# ★ 1 1y agoExplain → -
cti ⑂
Cyber Threat Intelligence Repository expressed in STIX 2.0
★ 1 1y agoExplain → -
CVE-2025-0282 ⑂
Ivanti Connect Secure IFT TLS Stack Overflow pre-auth RCE (CVE-2025-0282)
★ 1 1y agoExplain → -
ctrlaltrange ⑂
AI-based Ludus range configuration builder
★ 1 1y agoExplain → -
subroot ▣
Another subdomain bruteforcer
★ 1 1y agoExplain → -
UnlmtdCalc ▣
A python application that takes the Value of a Cineworld Unlimited card and then works out if it's worth while you getting one based upon your film choices
Python ★ 1 1y agoExplain → -
redsocial ▣
No description.
Shell ★ 1 1y agoExplain → -
SH ▣
No description.
PowerShell ★ 1 1y agoExplain → -
Kali_Setup ▣
Epic Kali Script, oracle and other thinfs need to be added soon.
Shell ★ 1 1y agoExplain → -
HoffPwn ▣
Hoff in Style
★ 1 1y agoExplain → -
ghostDebian ▣
GhostDeployment Script for Debian
Shell ★ 1 1y agoExplain → -
FSMF-BurpExtension ▣
Find Subdomains MoFo - Burp Extension WIP
Python ★ 1 1y agoExplain → -
cloudathost-debian ▣
Provision Script for Debian on CAC
Shell ★ 1 1y agoExplain → -
Bootspeed ▣
Check the boot speed of a windows machine
VBScript ★ 1 1y agoExplain → -
Spartacus ⑂
Spartacus DLL/COM Hijacking Toolkit
C# ★ 1 2y agoExplain → -
RamiGPT ⑂
Autonomous Privilege Escalation using OpenAI
★ 1 1y agoExplain → -
Malcore-Free-Courses ⑂
Free educational courses
★ 1 1y agoExplain → -
KrakenMask ⑂
Sleep obfuscation
★ 1 1y agoExplain → -
odinldr ⑂
Cobaltstrike Reflective Loader with Synthetic Stackframe
★ 1 1y agoExplain → -
gtunnel ⑂
A robust tunelling solution written in golang
★ 1 3y agoExplain → -
raptor ⑂
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, and perform research or attack/defense operations.
Python ★ 0 8d agoExplain → -
rpi-snmp-ups-synology-nas ⑂
Use apcupsd as a network UPS monitor for Synology NAS.
Shell ★ 0 6mo agoExplain → -
wordlewin
Give it the date and it'll solve the wordle for said date
Python ★ 0 6mo agoExplain → -
Havoc ⑂
The Havoc Framework
★ 0 6mo agoExplain → -
ADSpray
Active Directory Password Auditor in Python
Python ★ 0 6mo agoExplain → -
ADExplorerSnapshot ⑂
ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-object dumping to NDJSON.
★ 0 6mo agoExplain → -
WCrapware
No description.
PowerShell ★ 0 7mo agoExplain → -
Snaffler ⑂
a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
C# ★ 0 4mo agoExplain → -
LudusMCP ⑂
No description.
TypeScript ★ 0 6mo agoExplain → -
test
No description.
★ 0 7mo agoExplain → -
gdid-reversal ⑂
No description.
★ 0 18d agoExplain → -
sheepl ⑂
Sheepl : Creating realistic user behaviour for supporting tradecraft development within lab environments
Python ★ 0 27d agoExplain → -
bsides-leeds-2026-badge ⑂
The Artie the Owl badge for BSIDES Leeds 2026!
C++ ★ 0 1mo agoExplain → -
EDRChoker ⑂
A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
C ★ 0 1mo agoExplain → -
APC-Dash
No description.
HTML ★ 0 3mo agoExplain → -
packages-publish-oidc-example ⑂
Shows how to publish packages to Buildkite Registries using an OIDC token.
★ 0 3mo agoExplain → -
image ⑂
[mirror] Go supplementary image libraries
Go ★ 0 4mo agoExplain → -
configFiles
zsh stuffs
Shell ★ 0 4mo agoExplain → -
ludus_elastic_container ⑂
An Ansible role that installs "The Elastic Container Project" on a Linux system.
★ 0 4mo agoExplain → -
Certipy ⑂
Tool for Active Directory Certificate Services enumeration and abuse
★ 0 1y agoExplain → -
RepoManHistorian
Rewrite commit history with the power of automation
Python ★ 0 7mo agoExplain → -
LCA
AI Local Code Agent similar to Claude Code
Rust ★ 0 7mo agoExplain → -
errorism-template
No description.
JavaScript ★ 0 7mo agoExplain → -
DockerSpeedTest
No description.
HTML ★ 0 7mo agoExplain → -
CanaryPy
Python Canary Wrapper
Python ★ 0 7mo agoExplain → -
wsass ⑂
This is the tool to dump the LSASS process on modern Windows 11
C++ ★ 0 10mo agoExplain → -
Rubeus ⑂
Trying to tame the three-headed dog.
★ 0 10mo agoExplain → -
ludushound ⑂
LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via Ludus for controlled testing.
★ 0 10mo agoExplain → -
CVE-2025-53770 ⑂
POC
★ 0 1y agoExplain → -
regcertipy ⑂
Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does
★ 0 1y agoExplain → -
SelfDeletion-Updated ⑂
Updated version of a long known self deletion technique to work with 24H2.
★ 0 1y agoExplain → -
AI-PTAF ⑂
An open framework for evaluating and certifying AI-based penetration testing tools, aligned with industry standards like PTES, OSSTMM, and CREST.
★ 0 1y agoExplain → -
IncomeTaxCalc ▣
A basic python script that takes your weekly wage and works out how much tax you pay
Python ★ 0 1y agoExplain → -
hax ▣
No description.
★ 0 1y agoExplain → -
AM_Dump-Files ▣
No description.
★ 0 1y agoExplain → -
BOF-patchit ⑂
An all-in-one Cobalt Strike BOF to patch, check and revert AMSI and ETW for x64 process. Both syscalls and dynamic resolve versions are available.
★ 0 3y agoExplain → -
FindUnusualSessions ⑂
A tool to remotely detect unusual sessions opened on windows machines using RPC
★ 0 1y agoExplain → -
CVE-2021-1675 ⑂
CVE-2021-1675 Detection Info
★ 0 3y agoExplain → -
Defender_Exclusions-BOF ⑂
A BOF to determine Windows Defender exclusions.
C++ ★ 0 1y agoExplain → -
SharpDllProxy ⑂
Retrieves exported functions from a legitimate DLL and generates a proxy DLL source code/template for DLL proxy loading or sideloading
★ 0 6y agoExplain → -
NTHW ⑂
Not The Hidden Wiki - The largest repository of links related to cybersecurity
★ 0 1y agoExplain → -
perfect-loader ⑂
Load a dynamic library from memory by modifying the native Windows loader
★ 0 1y agoExplain → -
PyObscura ⑂
A python script that automates a C2 Profile build
★ 0 1y agoExplain → -
Malleable-CS-Profiles ⑂
A list of python tools to help create an OPSEC-safe Cobalt Strike profile.
★ 0 2y agoExplain → -
SourcePoint ⑂
SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
★ 0 1y agoExplain → -
pyMalleableC2 ⑂
Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.
★ 0 1y agoExplain → -
Interocitor ⑂
No description.
Go ★ 0 1y agoExplain → -
junkshell ⑂
No description.
★ 0 1y agoExplain → -
portainer_templates ⑂
Template file for new portainer setup [Portainer-CE]
★ 0 1y agoExplain → -
DitExplorer ⑂
Tool for viewing NTDS.dit
★ 0 1y agoExplain → -
ARM64_AmsiPatch ⑂
No description.
★ 0 1y agoExplain → -
OCRMe ⑂
Tool designed to exfiltrate OneDrive Business OCR Data
★ 0 1y agoExplain → -
Volumiser ⑂
No description.
C# ★ 0 1y agoExplain → -
BYOSI ⑂
Evade EDR's the simple way, by not touching any of the API's they hook.
★ 0 1y agoExplain → -
cmloot ⑂
No description.
Python ★ 0 1y agoExplain → -
pxe-hashcat ⑂
Hashcat module that can crack a password used to derive an AES-128 key with CryptDeriveKey from CryptoAPI
C ★ 0 1y agoExplain → -
BOF-RegSave ⑂
Dumping SAM / SECURITY / SYSTEM registry hives with a Beacon Object File
★ 0 5y agoExplain → -
selfmovingdll
No description.
★ 0 1y agoExplain → -
KrbRelayEx ⑂
No description.
★ 0 1y agoExplain →
No repos match these filters.