vinegrep's Stars
aquasecurity/tfsec
Tfsec is now part of Trivy
Pennyw0rth/NetExec
The Network Execution Tool
itm4n/PrivescCheck
Privilege Escalation Enumeration Script for Windows
SystemRage/py-kms
KMS Server Emulator written in Python
can1357/NoVmp
A static devirtualizer for VMProtect x64 3.x. powered by VTIL.
matterpreter/OffensiveCSharp
Collection of Offensive C# Tooling
rasta-mouse/ThreatCheck
Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.
deepzec/Bad-Pdf
Steal Net-NTLM Hash using Bad-PDF
Sentinel-One/CobaltStrikeParser
RedSiege/Egress-Assess
Egress-Assess is a tool used to test egress data detection capabilities
dievus/Oh365UserFinder
Python3 o365 User Enumeration Tool
netero1010/GhostTask
A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.
cube0x0/SharpSystemTriggers
Collection of remote authentication triggers in C#
mdsecactivebreach/Chameleon
Chameleon: A tool for evading Proxy categorisation
georgesotiriadis/Chimera
Automated DLL Sideloading Tool With EDR Evasion Capabilities
cjm00n/EvilSln
A New Exploitation Technique for Visual Studio Projects
peasead/elastic-container
Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
zer0condition/mhydeath
Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.
malcomvetter/Periscope
Fully Integrated Adversarial Operations Toolkit (C2, stagers, agents, ephemeral infrastructure, phishing engine, and automation)
Sw4mpf0x/PowerLurk
Malicious WMI Events using PowerShell
machine1337/TelegramRAT
Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions
Cr4sh/SmmBackdoorNg
Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks
pathtofile/SealighterTI
Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
JohnWoodman/remoteInjector
Inject remote template link into word document for remote template injection
0xJs/domain_audit
Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.
wquiles/aws-cloud-mindmaps
Mindmaps about AWS based on public information
Bw3ll/JOP_ROCKET
This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution for Windows jump-oriented programming. JOP ROCKET also finds the novel two-gadget dispatcher, which greatly expands what is possible with JOP.
unkvolism/Fuck-Etw
Bypass the Event Trace Windows(ETW) and unhook ntdll.
volexity/donut-decryptor
Retrieve inner payloads from Donut samples
itaymigdal/GhostNap
Sleep obfuscation for shellcode implants and their reflective shit