Starred repositories
A collection of techniques, examples and a little bit of theory for manually obfuscating PowerShell scripts to achieve AV evasion, compiled for educational purposes. The contents of this repository…
A collaborative, multi-platform, red teaming framework
SysWhispers on Steroids - AV/EDR evasion via direct system calls.
rasta-mouse / ThreatCheck
Forked from matterpreter/DefenderCheckIdentifies the bytes that Microsoft Defender / AMSI Consumer flags on.
A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
ScriptSentry finds misconfigured and dangerous logon scripts.
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Universal MCT wrapper script for all Windows 10/11 versions from 1507 to 21H2!
Chris Titus Tech's Windows Utility - Install Programs, Tweaks, Fixes, and Updates
This repo contains some Amsi Bypass methods i found on different Blog Posts.
BloodyAD is an Active Directory Privilege Escalation Framework
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Simply generates a wordpress plugin that will grant you a reverse shell once uploaded. I recommend installing Kali Linux, as msfvenom is used to generate the payload.
Information gathering framework for phone numbers
Install and Run Python Applications in Isolated Environments
Check syntax in Vim/Neovim asynchronously and fix files, with Language Server Protocol (LSP) support
PHP shells that work on Linux OS, macOS, and Windows OS.
Tool for Active Directory Certificate Services enumeration and abuse
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
Free and Open Source Reverse Engineering Platform powered by rizin
A cheat sheet that contains advanced queries for SQL Injection of all types.
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…