Stars
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Simple script to test if NLA (network level Authentication) is disabled.
Repository hosting a static list of Microsoft First party apps and Graph permissions that's updated daily
No-as-a-Service (NaaS) is a simple API that returns a random rejection reason. Use it when you need a realistic excuse, a fun “no,” or want to simulate being turned down in style.
Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox
Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
Tool for Active Directory Certificate Services enumeration and abuse
peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.
xforcered / RemoteMonologue
Forked from 3lp4tr0n/RemoteMonologueWeaponizing DCOM for NTLM Authentication Coercions
Run PowerShell command without invoking powershell.exe
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Rebuild of portspoof in GO with additional features.
extract remote timestamp from hping3 icmp replies
Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets extraction.
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Code included as part of the MustLearnKQL blog series
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
Bloodhound Reporting for Blue and Purple Teams
PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
Arsenal is just a quick inventory and launcher for hacking programs