This is your work, valued
Security Engineer
eximrce-CVE-2019-10149. simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.
★ 14sysmon-auto-install. Install and auto update scripts for sysmon and winlogbeat
★ 3wazuh-ntfy. custom ntfy integration for wazuh
★ 3gstack. Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
★ 126kcrush-forensics. Open-source desktop workbench for digital forensic analysis. Inspect ZIP/TAR/7z archives and iTunes/Android backups. Parse and view ABX, SQLite, SEGB, (B)PLIST, REALM, Protobuf, Logs,hex, JSON, XML, and more — all in one GUI.
★ 38ccl-segb. Module(s) related to reading SEGB (fka "Biome") data from iOS, mascOS, etc.
★ 35ScheduledSpy. A command line process execution monitor for Windows.
★ 8endpoint-ai-agent-abuse. EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.
★ 37wallpanel-android. WallPanel PRO is an Android application for Web Based Dashboards and Home Automation Platforms
★ 32Offensive-x64-Assembly. Collection of programs I made while learning assembly.
★ 66OffsetInspect. PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
★ 81geometrikks. GeoMetrikks is a real-time nginx access log ingestion and geo-location tracking service built with Litestar. It parses nginx access logs, performs GeoIP lookups, and stores geo-events and access logs in PostgreSQL with TimeScaleDB/PostGIS extensions. It can also integrate with CrowdSec.
★ 17floci. Light, fluffy, and always free - The AWS Local Emulator alternative
★ 18kMaliciousBrowserExtensions. This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one place. The CRX in this Repository are used to train AI Model behind ExterminAI. I hope this will allow others to explore the world of malicious browser extensions and their behaviour!
★ 29Offensive-COM. Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.
★ 135YaraRules. Collection of interesting Yara Rules
★ 16sigwood. Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.
★ 100windows-process-injection. A collection of techniques for process injection on Windows
★ 87awesome-reverse-engineering-and-malware-analysis. Reverse engineering & malware analysis, curated and verified disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other lists miss.
★ 76Proxywatch. ProxyWatch
★ 79threat-hunting-detections. Threat hunting queries, Sigma rules, and detection engineering research based on MITRE ATT&CK techniques.
★ 37harpyTools. Python
★ 18easy-floorplan. Interactive Home Assistant floorplan card with a visual drag-and-drop editor for walls, doors, furniture, text and device controls
★ 418gdid-reversal.
★ 694PhotoGIMP. A Patch for GIMP 3+ for Photoshop Users
★ 17kmwb-linux. Mouse Without Borders for Linux bidirectional keyboard, mouse & clipboard sharing with Windows
★ 50World-of-M365. A curated toolkit of M365 automation scripts designed to simplify management, accelerate workflows, and improve operational efficiency.
★ 52WindowsProtocolTestSuites. ⭐⭐ Join us at SambaXP for the SMB3 IO Lab (April 20-23, 2026), see upcoming Interoperability Events
★ 564GadgetSniper. Precision call-stack spoofing gadget hunter for x64 DLLs, powered by Iced disassembler
★ 19TABPE. A monthly Windows PE baseline dataset for Cyber security researchers
★ 24claude-skill-homeassistant. Claude Code skill to supercharge and manage all Home Assistant workflows
★ 767win32k-callback-detouring. Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
★ 106SindriKit. A foundational C library for building operationally credible offensive capabilities
★ 71AzurePentestingWiki. This is a wiki for Azure pentesting techniques. Powered by Zensical and GitHub Pages
★ 1Hollow. A shellcode loader generator with support for multiple injection techniques, built for red team engagements.
★ 99window-persistence-Privilege-Escalation. A complete hands-on reference of 67 Windows persistence techniques used by real-world APT groups. Each technique includes MITRE ATT&CK TTP mapping, known threat actor attribution, attack commands, verification steps, and cleanup — organized from No-Admin to Admin level. Built for red teamers, malware analysts, and cybersecurity learners.
★ 20MSRPC-to-ATTACK. A repository that maps commonly used attacks using MSRPC protocols to ATT&CK
★ 349Claude-Red. claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
★ 2.8koscp-resources. 2025 OSCP checklists for an easy pass
★ 8ha-tv-pip. This is an Android TV App, and Home Assistant Integration, designed to enable simple Picture in Picture notifications on your TV from Home Assistant.
★ 13QuickBars. The Official QuickBars for Home Assistant Repository
★ 365MemNixFS. Linux Memory Forensics Framework That Transforms Memory Dumps Into a Navigable Filesystem
★ 194ContentOps. Security content lifecycle management for Microsoft Sentinel and Microsoft Defender XDR.
★ 16signal-scanner. Bounded-state streaming scanner for web, source, and file content pipelines
★ 19WeatherPaper. WeatherPaper is a health and comfort-focused smart weather station designed around a 4.2-inch e-paper display and a custom PCB. Lasting over one year and a half on a single charge. Featured on XDA Developers!
★ 86HallWatch. Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.
★ 86voiden. Design, Test and Document APIs in plain Markdown. Compose Requests with API blocks. Reuse, Replace & Version everything just like code. Offline, Truly Git Native, No Lock-in.
★ 1.4kazure-sentinel-detection-engineering. 9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.
★ 5RedSEC. Red team log aggregation and correlation tool with MITRE ATT&CK mapping and SEC integration
★ 8DVAP. An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.
★ 26DCOMIllusionist. DCOM in memory and fileless lateral movement techniques through .Net deserilization
★ 280RoguePlanet. RoguePlanet Windows Defender Vulnerability
★ 1.6kQuery-Hub. CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here are automatically published to cql-hub.com , making them easily accessible to the community.
★ 76memgrep. Tool for grepping the memory of processes
★ 41invisible_playwright. Undetected Playwright automation in Python. Stealth-patched Firefox, anti-detect browser fingerprint in the engine, not injected. Passes bot detection.
★ 1.8kLogHound. Post-Exploitation EVTX Analyzer for BloodHound Mapping
★ 11aether. Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies. it works with a multi-layer confidence model that dramatically reduce the false positive rate and hunt for malicious behaviour.
★ 56nozzlenest. NozzleNest is a premium, next-generation 3D print organizer desktop application built with Electron, React, Vite, and SQLite for Windows.
★ 22ida-pro-mcp. AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
★ 11kpersisthunt. Linux Persistence Detection, Hunting and Artifact Collection script
★ 24L0p4Map. Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.
★ 429Armorer-Guard. Fast local Rust scanner for AI-agent prompt injection, credential leaks, exfiltration, and risky tool calls
★ 40KQLab. The self-hosted KQL query management platform for SOC teams
★ 22EtwWatcher. Browse and diff ETW provider snapshots across Windows builds. Backed by ETWInspector.
★ 40iocx. An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern threat‑analysis pipelines.
★ 27EventHawk. Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mode (Arrow/DuckDB) for 10M+ events.
★ 54vanguard. Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensics, disk collection, remote operations, and Velociraptor management. Works air-gapped, with automated timeline generation.
★ 154Impacket-IoCs. This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
★ 319wg.copyfail.patch. CVE-2026-31431 eBPF fix
★ 24cve_2026_31431. Exploit POC for CVE_2026_31431
★ 565copy-fail-CVE-2026-31431-IOC. Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation
★ 31FBps. Fast HTTP access control testing tool designed to discover 401 and 403 bypass vulnerabilities
★ 19FBps-lab. Intentionally vulnerable lab for exploring access control bypasses in misconfigured Nginx/Flask setups
★ 10so-crates. SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!
★ 563Titanis. Windows protocol library, including SMB and RPC implementations, among others.
★ 812PETriage. PETriage: A symbol-unified PE file reader for triage, built for multi-platform and multi-interface use.
★ 13clickdetect. ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, VictoriaLogs, PostgreSQL, DuckDB or any custom data source through a flexible integration layer.
★ 50Detections.AI. A mirror image of my detection rules
★ 164FaceDancer. FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading
★ 445toastfix-demo. Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with ClickFix-style lure
★ 18Notes.
★ 2.7kSilentNimvest. Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)
★ 107owLSM. Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
★ 280detection.studio. Convert Sigma rules to SIEM queries, directly in your browser.
★ 121nightMARE. Elastic Security Labs' malware analysis and reverse engineering library
★ 81rizin. UNIX-like reverse engineering framework and command-line toolset.
★ 3.7ksmda. SMDA is a minimalist recursive disassembler library that is optimized for accurate Control Flow Graph (CFG) recovery from memory dumps.
★ 261capstone. Capstone disassembly/disassembler framework for ARM, ARM64 (ARMv8), Alpha, BPF, Ethereum VM, HPPA, LoongArch, M68K, M680X, Mips, MOS65XX, PPC, RISC-V(rv32G/rv64G), SH, Sparc, SystemZ, TMS320C64X, TriCore, Webassembly, XCore and X86.
★ 8.9kLIEF. LIEF - Library to Instrument Executable Formats (C++, Python, Rust)
★ 5.5kKslDump. KslDump — Why bring your own knife when Defender already left one in the kitchen?
★ 398ADFT. Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)
★ 51PUA-encoder. A simple PUA encoder and a PoC
★ 3ha-mcp. The Unofficial and Awesome Home Assistant MCP Server
★ 4.2kVMkatz. Extract Windows credentials directly from VM memory snapshots and virtual disks
★ 1.5kXDRInternals. A PowerShell module for the Defender XDR portal
★ 127zombie-zip. Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.
★ 196LnkMeMaybe. Lnk crafting and research tools
★ 184bromure. Proper sandboxing for agentic coding and web browsing
★ 273XDRConverter. PowerShell
★ 24kunai. Threat-hunting tool for Linux
★ 1.1klazytail. Log viewer for app development
★ 219DLLHijackHunter. Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.
★ 395binary-ninja-headless-mcp. Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools.
★ 228lnav. Log file navigator
★ 10kmquire. Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug info.
★ 180TTPRunner. Run TTPs, with AI!
★ 140WSABuilds. Run Windows Subsystem For Android on your Windows 10 and Windows 11 PC using prebuilt binaries with Google Play Store (MindTheGapps) and/or Magisk or KernelSU (root solutions) built in.
★ 18kVEN0m-Ransomware. Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.
★ 366stagehand. The SDK For Browser Agents
★ 24kskyvern. Automate browser based workflows with AI
★ 23kmaps_scanner. MAPS cloud scanner and response parser for Microsoft Defender research.
★ 94defender_overview. Overview of MS Defender
★ 155Kittysploit-framework. Python Exploitation Framework, V8 Engine Debugger, Proxy interceptor, marketplace, post-exploitation, backdoor generator,....
★ 561deskflow. Share a single keyboard and mouse between multiple computers.
★ 28kAegis. Open-source EDR for AI agents. Monitor processes, files, network, and behavior of autonomous AI agents.
★ 140ksentinel. Linux kernel integrity monitor for detecting syscall hooking
★ 88DC3-MWCP. DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, filenames, and mutex names.
★ 349studio. Workflow automation for Security Teams
★ 350lnk-it-up. Project for generating and identifying deceptive LNK files.
★ 375ElephantPoint. C#
★ 62EarlyBird-APC-Code-Injection. EarlyBird APC Injection is a stealthy process injection technique that queues malicious shellcode into a suspended thread of a newly created process. Once the thread is resumed, the payload executes, making detection and analysis more difficult.
★ 10ColdWer. Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
★ 144eden. A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)
★ 135InlineExecute-Assembly. InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module
★ 764KernelCallbackTable-Injection-PoC. Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijack execution flow.
★ 275SentinelLabs_RevCore_Tools. The Windows Malware Analysis Reversing Core Tools
★ 100Awesome-AI-Hacking-Agents. List of AI Hacking Agents
★ 622malasada. Linux Shared Library to Shellcode Loader
★ 100ConditionalAccessPolicies. Defense in Depth CA Policies
★ 37nathanmcnulty. PowerShell
★ 428opengrep. 🔎 Static code analysis engine to find security issues in code.
★ 2.9kFlask-Unsign. Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
★ 658MapsModelsImporter. A Blender add-on to import models from google maps
★ 2.8kjsdeob-workbench. Reverse engineer obfuscated JavaScript visually. Chain transforms, inspect AST changes, write reusable deobfuscation plugins.
★ 118LOLAPI. Living Off The Land API
★ 61Threat-Hunting. Threat Hunting queries of multiple platforms
★ 76cleanldap. C
★ 194malicious_extension_sentry. Malicious Extension Database
★ 189w11_shadow_copies. Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11
★ 84awesome-appsec-interview. A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews
★ 23swarmer. A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN
★ 152bulk_extractor-rec. It is based on bulk_extractor (https://github.com/simsong/bulk_extractor) and add scanners for record carving
★ 43vss_carver. Carves and recreates VSS catalog and store from Windows disk image.
★ 101LogFileParser. Parser for $LogFile on NTFS
★ 218timeline-downloader. Go
★ 84PixelCode-Attack. Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing them inside images or videos. A lightweight loader retrieves the media file, reconstructs the original binary and executes it in memory. This project highlights unconventional data delivery.
★ 171Get-InjectedThreadEx. Fork of Get-InjectedThread - https://gist.github.com/jaredcatkinson/23905d34537ce4b5b1818c3e6405c1d2
★ 55chisel-ng. Chisel new generation, written in rust. SSH under WSS with some customization.
★ 136Hacking-Cheatsheets. A comprehensive collection of penetration testing cheatsheets, guides, and tools.
★ 522LiveResponse. M365 MDATP Live Response sample scripts
★ 82gargoyle. Historical Windows temporal memory-state research artifact for studying time-bound memory observations, validation limits, and defensive visibility.
★ 909shield_optimizer. Rust
★ 877PSDecode. PowerShell script for deobfuscating encoded PowerShell scripts
★ 436ArgFuscator.net. ArgFuscator.net is an open-source, stand-alone web application that helps generate obfuscated command lines for common system-native executables.
★ 427maldump. Multi-quarantine extractor
★ 59Microsoft-365-PowerShell-Scripts. PowerShell scripts for managing, reporting, and auditing Microsoft 365 tenants across Entra ID, Exchange, SharePoint, Teams, Intune, and more.
★ 69usnjrnl_rewind. USN Journal full path builder
★ 69browser-use. 🌐 Make websites accessible for AI agents. Automate tasks online with ease.
★ 107kxss-labs. small set of scripts to practice exploit XSS and CSRF vulnerabilities
★ 65FalconHound. FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.
★ 824creddump. Automatically exported from code.google.com/p/creddump
★ 284Security-Detections-MCP. MCP to help Defenders Detection Engineer Harder and Smarter
★ 466VanillaWindowsReference. A repo that contains recursive directory listings (using PowerShell) of a vanilla (clean) install of every Windows OS version to compare and see what's been added with each update. Use these CSVs to create your own known good hash sets!
★ 202SQLServerForensics. SQL Server Forensics
★ 7Research_Successful_Errors. Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.
★ 121libvshadow. Library and tools to access the Volume Shadow Snapshot (VSS) format
★ 116ADTrapper. Hunt Smarter, Hunt Harder
★ 199bstrings. A better strings utility!
★ 151appcompatprocessor. "Evolving AppCompat/AmCache data analysis beyond grep"
★ 212malpedia-flossed. FLARE floss applied to all unpacked+dumped samples in Malpedia, pre-processed for further use.
★ 83Invoke-Phant0m. Windows Event Log Killer
★ 11DumpGuard. Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
★ 720dumpguard_bof. Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.
★ 220awesome-attack-surface-management. A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).
★ 37SysmonConfigPusher2. Sysmon Config Pusher - Modernized
★ 45DiaSymbolView. PDB file inspection tool
★ 137witr. Why is this running? Trace any process, port, container, or file back to what started it - CLI + TUI.
★ 18kEvilNeko. Python
★ 79EvilnoVNC. Ready to go Phishing Platform
★ 1.2kMSFinger. Microsoft Network Service Fingerprinting Tool
★ 73NEBULA. Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques
★ 130awesome-dfir-skills. A curated collection of DFIR skills and workflows for InfoSec practitioners.
★ 319nodecast-tv. A self-hosted web application that lets you stream Live TV, Movies, and Series from your Xtream Codes or M3U provider directly in your browser. It's built with performance in mind and handles large libraries smoothly.
★ 1.4kedgeshark. Discover and capture container network traffic from your comfy desktop Wireshark, using a containerized service and a Wireshark plugin.
★ 586Rinkhals. Custom firmware for the Anycubic Kobra series of 3D printers (Kobra 2 Pro, Kobra 3, Kobra 3 V2, Kobra S1, Kobra 3 Max and Kobra S1 Max)
★ 898ms-photos_NTLM_Leak. New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click
★ 209agentic-threat-hunting-framework. ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
★ 347wirebrowser. Wirebrowser is a CDP-based runtime instrumentation platform for the browser. Think Frida, but for JavaScript running in Chrome — without monkeypatching.
★ 498KustoHawk. KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Microsoft Sentinel environments.
★ 158vulnerable_notifier. A Webhook application to demonstrate SSRF vulnerabilities
★ 2phantomraven-hunter. Shell
★ 14EvilMist. EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. EvilMist aims to streamline cloud-focused red-team workflows and improve the overall security posture of cloud infrastructures
★ 145CVE-2025-55182-research. CVE-2025-55182 POC
★ 796krakenhashes. Go
★ 398Crow-Eye. Windows forensics Engine
★ 109SentinelNav. SentinelNav: zero-dependency, pure Python binary visualization and forensics tool.
★ 146COM-Hunter. COM Hijacking VOODOO
★ 387safe-chain. Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.
★ 1.6kghost. Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.
★ 380data-breach. A continuously updated resource that catalogs confirmed data breaches from across the globe. Each entry includes the breach name, usually aligned with the impacted organization, and the date of the incident.
★ 64RegPersist. a BOF implementation of various registry persistence methods
★ 98DonPwner. Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database
★ 267ADCSDevilCOM. A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using the MS-WCCE protocol over DCOM and It bypasses the traditional endpoint mapper requirement by using SMB directly.
★ 168