Skip to content

VolenBait/OSEP-Learn

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 

Repository files navigation

OSEP-Learn

工具站

https://gtfobins.github.io/

技术

绕过amsi:https://pentestlaboratories.com/2021/05/17/amsi-bypass-methods/

工具和脚本:

BloodHoundL:https://github.com/BloodHoundAD/BloodHound

sharpshooter:https://github.com/mdsecactivebreach/SharpShooter

mimikatz: https://github.com/gentilkiwi/mimikatz

amsibypass:https://github.com/boku7/injectAmsiBypass

OSEP-Code-Snippets:https://github.com/chvancooten/OSEP-Code-Snippets

好用的项目与使用场景

1、Bypass-CLM,用于绕过Powershell Constrained语言模式: https://github.com/calebstewart/bypass-clm

2、混淆工具,可用于混淆Bypass-CLM: https://github.com/XenocodeRCE/neo-ConfuserEx

3、⭐BloodHound: https://github.com/BloodHoundAD/BloodHound

4、⭐PowerViews,枚举: https://github.com/PowerShellMafia/PowerSploit/tree/master/Recon

5、PowerUp,提权: https://github.com/PowerShellMafia/PowerSploit/blob/master/Privesc/PowerUp.ps1

6、⭐PPLKiller,用于禁用LSA保护: https://github.com/RedCursorSecurityConsulting/PPLKiller

7、Rubeus: https://github.com/GhostPack/Rubeus

8、PrintSpoofer,存在Seimpersonate权限并开启spoofer服务时可以提权: https://github.com/itm4n/PrintSpoofer

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published