Pinned Repositories
AMSI.fail
C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.
AzureC2Relay
AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile.
BetterSafetyKatz
Fork of SafetyKatz that dynamically fetches the latest pre-compiled release of Mimikatz directly from gentilkiwi GitHub repo, runtime patches signatures and uses SharpSploit DInvoke to PE-Load into memory.
CobaltBus
Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus
NetLoader
Loads any C# binary in mem, patching AMSI + ETW.
ObfuscatedSharpCollection
Attempt at Obfuscated version of SharpCollection
SharpCollection
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
SharpDllProxy
Retrieves exported functions from a legitimate DLL and generates a proxy DLL source code/template for DLL proxy loading or sideloading
SharpProxyLogon
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection
TeamFiltration
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
Flangvik's Repositories
Flangvik/SharpCollection
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
Flangvik/TeamFiltration
TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts
Flangvik/NetLoader
Loads any C# binary in mem, patching AMSI + ETW.
Flangvik/AMSI.fail
C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.
Flangvik/CobaltBus
Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus
Flangvik/ObfuscatedSharpCollection
Attempt at Obfuscated version of SharpCollection
Flangvik/Bobber
Bounces when a fish bites - Evilginx database monitoring with exfiltration automation
Flangvik/QRucible
Python utility that generates "imageless" QR codes in various formats
Flangvik/SharpAppLocker
C# port of the Get-AppLockerPolicy PS cmdlet
Flangvik/collector
Utility to analyse, ingest and push out credentials from common data sources during an internal penetration test.
Flangvik/Ethical-Hacking-101-Cheat-Sheet
Cheat Sheet High School Student
Flangvik/remote_wrapper
Extensible Mythic Wrapper that allows payload wrapping to occur on a remote host
Flangvik/statistically-likely-usernames
Wordlists for creating statistically likely username lists for use in password attacks and security testing
Flangvik/WAMBam
Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post
Flangvik/yetAnotherObfuscator
C# obfuscator that bypass windows defender
Flangvik/evilgophish
evilginx2 + gophish
Flangvik/ForgeCert
"Golden" certificates
Flangvik/evilginx2
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Flangvik/kerbrute
A tool to perform Kerberos pre-auth bruteforcing
Flangvik/ADExplorerSnapshot.py
ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound, and also supports full-object dumping to NDJSON.
Flangvik/parley
Tree of Attacks (TAP) Jailbreaking Implementation
Flangvik/smartbrute
Password spraying and bruteforcing tool for Active Directory Domain Services
Flangvik/thanatos
Mythic C2 agent targeting Linux and Windows hosts written in Rust
Flangvik/TokenStomp
C# implementation of the token privilege removal flaw discovered by @GabrielLandau/Elastic
Flangvik/Apollo
A .NET Framework 4.0 Windows Agent
Flangvik/impacket
Impacket is a collection of Python classes for working with network protocols.
Flangvik/Nemesis
An offensive data enrichment pipeline
Flangvik/RustHound-CE
Active Directory data ingestor for BloodHound Community Edition written in Rust. 🦀
Flangvik/SharpC2-Docs
Flangvik/Ubuntu-MacBook-Norwegian-keyboard
Ubuntu + Norwegian keyboard symbols for Macbook Pro keyboards