This is your work, valued
WinPwn. Automation for internal Windows Penetrationtest / AD-Security
3.7kPentest-Tools.
2.4kAmsi-Bypass-Powershell. This repo contains some Amsi Bypass methods i found on different Blog Posts.
2.2kPowerSharpPack. PowerShell
1.7kOffensiveVBA. This repo covers some code execution and AV Evasion methods for Macros in Office documents
1.3kCreds. Some usefull Scripts and Executables for Pentest & Forensics
1.2kMultiPotato. C++
536Caro-Kann. Encrypted shellcode Injection to avoid Kernel triggered memory scans
429SharpImpersonation. A User Impersonation tool - via Token or Shellcode injection
422Invoke-SharpLoader. PowerShell
360Ruy-Lopez. C
322SharpNamedPipePTH. Pass the Hash to a named pipe for token Impersonation
310Nim-RunPE. A Nim implementation of reflective PE-Loading from memory
295NimGetSyscallStub. Get fresh Syscalls from a fresh ntdll.dll copy
232SharpVeeamDecryptor. Decrypt Veeam database passwords
225NamedPipePTH. Pass the Hash to a named pipe for token Impersonation
145SyscallAmsiScanBufferBypass. AmsiScanBufferBypass using D/Invoke
136Excel-Phish. Phish password protected Excel-Files
109Nim_DInvoke. D/Invoke implementation in Nim
101Sharp-HackBrowserData. C# binary with embeded golang hack-browser-data
100Get-System-Techniques. PowerShell
98RDPThiefInject. RDPThief donut shellcode inject into mstsc
88NimShellcodeFluctuation. ShellcodeFluctuation PoC ported to Nim
77My-starred-Repositories. This is my starred repositories including the description for each tool. Makes search/filter over them easier.
70Nim_CBT_Shellcode. CallBack-Techniques for Shellcode execution ported to Nim
61Invoke-Sharpcradle. Load C# Code straight to memory
56SharpOxidResolver. IOXIDResolver from AirBus Security/PingCastle
52BitwardenDecryptBrute. Wordlist attacks on Bitwarden data.json files
48LDAP-Signing-Scanner. A little scanner to check the LDAP Signing state
46SharpPolarBear. Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
37S3cur3Th1sSh1t.
33SharpByeBear. AppXSVC Service race condition - privilege escalation
29SharpUnhooker. C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)
24nim-strenc. string encryption in Nim
19MailSniper. MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
19xencrypt. A PowerShell script anti-virus evasion tool
18SharpLigolo. C# wrapper for ligolo
17TeamViewerDecrypt. PowerShell
17OffensiveNim. My experiments in weaponizing Nim (https://nim-lang.org/)
16Grouper. A PowerShell script for helping to find vulnerable settings in AD Group Policy.
16the-book-of-secret-knowledge. A collection of awesome lists, manuals, blogs, hacks, one-liners, cli/web tools and more. Especially for System and Network Administrators, DevOps, Pentesters or Security Researchers.
15DomainPasswordSpray. DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
14EmpEISDecrypt. Decrypt Matrix42 Empirum /EIS Passwords
14Invoke-WMI-Information. Straight forward script for WMI information gathering (local or remote)
13AMSITrigger. The Hunt for Malicious Strings
13SharpRDP. Remote Desktop Protocol .NET Console Application for Authenticated Command Execution
12PrivescCheck. Privilege Escalation Enumeration Script for Windows
10WinFor. Powershell script to execute different forensic Powershell functions / tools on a compromised host
9AD-Attack-Defense. Active Directory Security For Red & Blue Team
9CheckPlease. Sandbox evasion modules written in PowerShell, Python, Go, Ruby, C, C#, Perl, and Rust.
8p0wnedShell. PowerShell Runspace Post Exploitation Toolkit
8Shellcode-Hide. This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)
7awesome-windows-domain-hardening. A curated list of awesome Security Hardening techniques for Windows.
7mitmAP. 📡 A python program to create a fake AP and sniff data.
7metasploit-framework. Metasploit Framework
7