vinegrep's Stars
aquasecurity/tfsec
Tfsec is now part of Trivy
zer0condition/mhydeath
Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.
0xJs/domain_audit
Audit tool for Active Directory. Automates a lot of checks from a pentester perspective.
itm4n/PrivescCheck
Privilege Escalation Enumeration Script for Windows
Bw3ll/JOP_ROCKET
This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution for Windows jump-oriented programming. JOP ROCKET also finds the novel two-gadget dispatcher, which greatly expands what is possible with JOP.
deepzec/Bad-Pdf
Steal Net-NTLM Hash using Bad-PDF
machine1337/TelegramRAT
Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions
georgesotiriadis/Chimera
Automated DLL Sideloading Tool With EDR Evasion Capabilities
iknowjason/Awesome-CloudSec-Labs
Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.
byt3bl33d3r/SpamChannel
Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)
danielpoliakov/lisa
Sandbox for automated Linux malware analysis.
f-bader/TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2
rvrsh3ll/TokenTactics
Azure JWT Token Manipulation Toolset
GhostPack/PSPKIAudit
PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.
fortalice/modifyCertTemplate
ADCS cert template modification and ACL enumeration
FalconForceTeam/FalconFriday
Hunting queries and detections
ayoubfaouzi/windows-exploitation
My notes while studying Windows exploitation
PeterDaveHello/chkdomain
🔍 Discover if a domain is resolvable or blocked by secure DNS and Ad-blocking services, and experience the innovative idea of DaaS - DNS as an Intelligence Service.
slemire/WSPCoerce
PoC to coerce authentication from Windows hosts using MS-WSP
r3motecontrol/Ghostpack-CompiledBinaries
Compiled Binaries for Ghostpack
dani-garcia/vaultwarden
Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs
WKL-Sec/dcomhijack
Lateral Movement Using DCOM and DLL Hijacking
unode/firefox_decrypt
Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles
gtworek/PSBits
Simple (relatively) things allowing you to dig a bit deeper than usual.
epi052/osed-scripts
bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
CyberSecurityUP/OSCE3-Complete-Guide
OSWE, OSEP, OSED, OSEE
CognisysGroup/HadesLdr
Shellcode Loader Implementing Indirect Dynamic Syscall , API Hashing, Fileless Shellcode retrieving using Winsock2
FourCoreLabs/LolDriverScan
Scan vulnerable drivers on Windows with loldrivers.io
ldpreload/BlackLotus
BlackLotus UEFI Windows Bootkit
glebarez/padre
Blazing fast, advanced Padding Oracle exploit