This is your work, valued

John Lambert

Elite
@JohnLaTwC

@JohnLaTwC Security Fellow and Corporate Vice President, Microsoft Security

Shared. Shared Blogs and Notebooks

499

PyPowerShellXray. Python script to decode common encoded PowerShell scripts

216

MSRC. Scripts for interacting with MSRC portal data

77

Bluehat2018GraphWorkshop. Bluehat 2018 Graphs for Security Workshop

42

MacroJob. Proof of concept VBA code to add to Normal.dot to put restrictions on Word

40

EvilOSX. A pure python, post-exploitation, RAT (Remote Administration Tool) for macOS / OSX.

10

Mandiant-Azure-AD-Investigator. PowerShell

3

XLMMacroDeobfuscator. Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)

3

Bella. Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

2

pe-sieve. Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

2

CustomKeyboardLayoutPersistence. Achieve execution using a custom keyboard layout

2

Reports. HTML

2

SharpUp. SharpUp is a C# port of various PowerUp functionality.

1

SharpC2. Command and Control Framework written in C#.

1

EDRSandblast. C

1

ocsf-schema. OCSF Schema

1

CS-Remote-OPs-BOF. C

1

PSBits. Simple (relatively) things allowing you to dig a bit deeper than usual.

1

rpcfirewall. C++

1

xPipe. Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions

1

PPLdump. Dump the memory of a PPL with a userland exploit

1

DLL-Hijack-Search-Order-BOF. DLL Hijack Search Order Enumeration BOF

1

InlineExecute-Assembly. InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

1

DarkLoadLibrary. LoadLibrary for offensive operations

1

LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

1

sunburst_countermeasures. YARA

1

WDATPAPI. WDATP API Sample

1

DidierStevensSuite. Please no pull requests for this repository. Thanks!

1

Raccine. A Simple Ransomware Vaccine

1

msticpy. Microsoft Threat Intelligence Security Tools

1

CCCS-Yara. YARA rule metadata specification and validation utility

1

CS-Situational-Awareness-BOF. Situational Awareness commands implemented using Beacon Object Files

1

TaskManagerBitmap. Displays a bitmap on Task Manager's CPU activity view. For systems with > 64 CPUs.

1

gcat. A PoC backdoor that uses Gmail as a C&C server

1

WinRpcFunctions. PowerShell

1

Firewall_Walker_BOF. A BOF to interact with COM objects associated with the Windows software firewall.

1

RAT-via-Telegram. Windows Remote Administration Tool via Telegram

1

signature-base. Signature base for my scanner tools

1

metasploit-framework. Metasploit Framework

1

CrowdFMS. CrowdStrike Feed Management System

1