Pinned Repositories
backdoorppt
transform your payload.exe into one fake word doc (.ppt)
BHUSA2018_Sysmon
All materials from our Black Hat 2018 "Subverting Sysmon" talk
Ciphey
Automated decryption tool
commando-vm
CRT
Contact: CRT@crowdstrike.com
dfirtrack
DFIRTrack - The Incident Response Tracking Application
domainhunter
Checks expired domains, bluecoat categorization, and Archive.org history to determine good candidates for phishing and C2 domain names
krackattacks-test-ap-ft
ProcessSpawnControl
Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launched processes, and gives the analyst the option to either keep the process suspended, or to resume it.
WindowsDefenderATP-Hunting-Queries
Sample queries for Advanced hunting in Windows Defender ATP
0utCode's Repositories
0utCode/domainhunter
Checks expired domains, bluecoat categorization, and Archive.org history to determine good candidates for phishing and C2 domain names
0utCode/BHUSA2018_Sysmon
All materials from our Black Hat 2018 "Subverting Sysmon" talk
0utCode/Enterprise-Registration-Data-of-Chinese-Mainland
**大陆 31 个省份1978 年至 2019 年一千多万工商企业注册信息,包含企业名称、注册地址、统一社会信用代码、地区、注册日期、经营范围、法人代表、注册资金、企业类型等详细资料。This repository is an dataset of over 10,000,000 enterprise registration data of 31 provinces in Chinese mainland from 1978 to 2019.【工商大数据】、【企业信息】、【enterprise registration data】。
0utCode/krackattacks-test-ap-ft
0utCode/ProcessSpawnControl
Process Spawn Control is a Powershell tool which aims to help in the behavioral (process) analysis of malware. PsC suspends newly launched processes, and gives the analyst the option to either keep the process suspended, or to resume it.
0utCode/WindowsDefenderATP-Hunting-Queries
Sample queries for Advanced hunting in Windows Defender ATP
0utCode/backdoorppt
transform your payload.exe into one fake word doc (.ppt)
0utCode/Ciphey
Automated decryption tool
0utCode/commando-vm
0utCode/CRT
Contact: CRT@crowdstrike.com
0utCode/dfirtrack
DFIRTrack - The Incident Response Tracking Application
0utCode/EQGRP
Decrypted content of eqgrp-auction-file.tar.xz
0utCode/greyenergy-unpacker
Toolkit collection developed to help malware analysts dissecting and detecting the packer used by GreyEnergy samples.
0utCode/hello-world
just test
0utCode/hsn2-razorback
0utCode/Invoke-WMILM
0utCode/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
0utCode/Mandiant-Azure-AD-Investigator
0utCode/pics
Posters, drawings...
0utCode/pumpkin-book
《机器学习》(西瓜书)公式推导解析,在线阅读地址:https://datawhalechina.github.io/pumpkin-book
0utCode/signature-base
Signature base for my scanner tools
0utCode/SILENTTRINITY
An asynchronous post-exploitation agent powered by Python, IronPython, C# and .NET's DLR
0utCode/WAF-bypass
0utCode/wicked_cool_shell_scripts_2e
Full shell scripts for the second edition of Wicked Cool Shell Scripts
0utCode/winchecksec
Checksec, but for Windows