Stars
PowerSploit - A PowerShell Post-Exploitation Framework
Six Degrees of Domain Admin
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
Empire is a PowerShell and Python post-exploitation agent.
A Collection of Scripts Which Disable / Remove Windows 10 Features and Apps
This repository has been moved to https://codeberg.org/janikvonrotz/awesome-powershell. Please visit the new location for the latest updates.
BC-SECURITY / Empire
Forked from EmpireProject/EmpireEmpire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
PowerShell script for automation of routine tasks done after fresh installations of Windows 10 / Server 2016 / Server 2019
A repository of sysmon configuration modules
PowerShell functions and scripts (Azure, Active Directory, SCCM, SCSM, Exchange, O365, ...)
My musings with PowerShell
Remote Desktop entirely coded in PowerShell.
PowerTools is a collection of PowerShell projects with a focus on offensive operations.
The goal of this repository is to document the most common techniques to bypass AppLocker.
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…
Adversary Tactics - PowerShell Training
Various PowerShell functions and scripts
Cmd.exe Command Obfuscation Generator & Detection Test Harness
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber
A script for advanced discovery of Privileged Accounts - includes Shadow Admins
A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!)
Robust and practical application control for Windows
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.