Samirbous's Stars
Mr-Un1k0d3r/EDRs
fortra/nanodump
The swiss army knife of LSASS dumping
Dec0ne/KrbRelayUp
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
vxunderground/VX-API
Collection of various malicious functionality to aid in malware development
rootsecdev/Azure-Red-Team
Azure Security Resources and Notes
0xrawsec/whids
Open Source EDR for Windows
elastic/protections-artifacts
Elastic Security detection content for Endpoint
daem0nc0re/TangledWinExec
PoCs and tools for investigation of Windows process execution techniques
trendmicro/tlsh
decoder-it/LocalPotato
naksyn/Pyramid
a tool to help operate in EDRs' blind spots
hakril/PythonForWindows
A codebase aimed to make interaction with Windows and native execution easier
mdecrevoisier/EVTX-to-MITRE-Attack
Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
gabriellandau/PPLFault
zblurx/dploot
DPAPI looting remotely and locally in Python
med0x2e/NTLMRelay2Self
An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).
cyberark/RPCMon
RPC Monitor tool based on Event Tracing for Windows
antonioCoco/MalSeclogon
A little tool to play with the Seclogon service
Kudaes/LOLBITS
** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for EDR user-mode hooking evasion.
m417z/winapiexec
A small tool that allows to run WinAPI functions through command line parameters
g3rzi/HackingKubernetes
This repository contain any information that can be used to hack Kubernetes
gabriellandau/ShadowStackWalk
Finding Truth in the Shadows
elastic/Silhouette
Keep it secret, keep it safe
elastic/die-python
Native Python3 bindings for @horsicq's Detect-It-Easy
decoder-it/Troopers24
AzAgarampur/byeintegrity9-uac
ionescu007/r0ak
elastic/llm-detection-proxy
A proxy tool for detecting and logging LLM queries to Elasticsearch.
elastic/DaC-Reference
DaC Repo to store the reference documentation and detection-rules management with Elastic rules.
elastic/endpoint-shell
Endpoint Response Shell