- SL,UT
Stars
PEN-300 collection to help you on your exam.
Wordlist, rules and masks from Kaonashi project (RootedCON 2019)
A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule
Orange Cyberdefense mindmaps
A workshop about Malware Development
Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
File upload vulnerability scanner and exploitation tool.
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments…
PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
ScareCrow - Payload creation framework designed around EDR bypass.
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
A post exploitation framework designed to operate covertly on heavily monitored environments
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
A centralized source of all AWS IAM privilege escalation methods released by Rhino Security Labs.
Some of my security stuff and vulnerabilities. Nothing advanced. More to come.
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no trace.
Active Directory Assessment and Privilege Escalation Script
RedSnarf is a pen-testing / red-teaming tool for Windows environments
Convert Cobalt Strike profiles to modrewrite scripts
Various scripts for different malware families
Automate creating resilient, disposable, secure and agile infrastructure for Red Teams.
Wiki to collect Red Team infrastructure hardening resources