This is your work, valued
Security Research @ SpecterOps
Misconfiguration-Manager. Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
★ 1.2kwhoamsi. An effort to track security vendors' use of Microsoft's Antimalware Scan Interface
★ 255Journey_to_OSCE. A curated collection of resources that may be beneficial for anyone pursuing the OSCE.
★ 46OSCE-Prep. A list of freely available resources that can be used as a prerequisite before taking OSCE.
★ 4ElevateKit. The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.
★ 3ShellcodeWrapper. Shellcode wrapper with encryption for multiple target languages
★ 3windows-itpro-docs. This is used for contributions to the Windows 10 content for IT professionals on docs.microsoft.com.
★ 2win32. Public mirror for win32-pr
★ 2osed-scripts. bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
★ 2scripts. Python
★ 2shellcode-runners. Various shellcode runners
★ 2msf_rc_scripts.
★ 2docker-bloodhound. BloodHound Docker Ready to Use
★ 2.github. Python
★ 1chronology. SpecterOps Historical Records
★ 1minidump. Simple C# program to call MiniDumpWriteDump to dump LSASS memory.
★ 1PetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
★ 1MSSQL_Scripts. Various scripts/tools for enumerating and abusing MSSQL.
★ 1Whisker. Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
★ 1bypasses. C#
★ 1win_api. Learning the arcane arts of the Windows API.
★ 1Advanced-Process-Injection-Workshop. C++
★ 1PEzor. Open-Source PE Packer
★ 1LdapRelayScan. Check for LDAP protections regarding the relay of NTLM authentication
★ 1SharpDPAPI. SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
★ 1dnSpy. .NET debugger and assembly editor
★ 1Apollo. A .NET Framework 4.0 Windows Agent
★ 1personal_site. JavaScript
★ 1WinDbg-Samples. Sample extensions, scripts, and API uses for WinDbg.
★ 1printspoofer.net. C#
★ 1Seatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
★ 1rdpthief_dllinjection. C#
★ 1SCShell. SCShell implementation from scratch done as part of the PEN-300 course.
★ 1Jailbreaker-CE. Jailbreaker is a local evaluation tool for testing chatbot and agent-style systems against jailbreak, prompt-injection, and related failure modes.
★ 76ynab-mcp-server. YNAB MCP server with custom skills
★ 84ludus_sccm. An Ansible collection that installs an SCCM deployment with optional configurations.
★ 16LDAP-Bof-Collection. Collection of many ldap bofs for domain enumeration and privilege escalation. Created for use with the Adaptix C2.
★ 102ghostsurf. NTLM HTTP relay tool with SOCKS proxy for browser session hijacking
★ 180flare-learning-hub. Free educational content on reverse engineering and malware analysis from the FLARE team
★ 1.4kWhoYouCalling. Records an executable's network activity into a Full Packet Capture file (.pcap) and much more.
★ 477python-wcfbin. A python library for converting between WCF binary xml and plain xml.
★ 43BloodHoundOperator. BloodHound PowerShell client
★ 83printerbugnew. The DCERPC only printerbug.py version
★ 234bhopengraph. A python library to create BloodHound OpenGraphs
★ 65tiny11builder. Scripts to build a trimmed-down Windows 11 image.
★ 19kfustercluck. POC tool to abuse windows server failover clusters
★ 57BASIC-M6502. Microsoft BASIC for 6502 Microprocessor - Version 1.1
★ 4.5kAzADServicePrincipalInsights. Insights and change tracking on Microsoft Entra ID Service Principals (Enterprise Applications, Applications and Managed Identities)
★ 254InsideOLE. Companion code for Inside OLE 2nd Edition, published in 1995
★ 21RAIWhateverTrigger. Local SYSTEM auth trigger for relaying - X
★ 160pyenv. Simple Python version management
★ 45kpyenv-virtualenv. a pyenv plugin to manage virtualenv (a.k.a. python-virtualenv)
★ 6.7kroadtools_hybrid. Hybrid AD utilities for ROADtools
★ 111mprecon. a small script to collect information from a management point
★ 37SharpSuccessor. SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.
★ 421bloodhound_mcp. A Model Context Protocol (MCP) server to converse with data in Bloodhound
★ 118FaceDancer. FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading
★ 445Misconfiguration-Manager. Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
★ 1.2kbbot. The recursive internet scanner for hackers. 🧡
★ 10kSCCMVNC. A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications. This can be done without requiring access to SCCM server.
★ 121Invoke-RunAsWithCert. A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.
★ 178LocalKdc. Info on how to use Kerberos KDC on a non-domain joined host
★ 54apeman. AWS Attack Path Management Tool - Walking on the Moon
★ 264FalconHound. FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.
★ 824lsa-whisperer. Tools for interacting with authentication packages using their individual message protocols
★ 438GptHidra. GptHidra is a Ghidra plugin that uses the OpenAI Chat GPT to explain functions. With GptHidra, you can easily understand the purpose and behavior of functions in your codebase. Now with GPT4 Support!
★ 401Gepetto. IDA plugin which queries language models to speed up reverse-engineering
★ 3.5ktiny_tracer. A Pin Tool for tracing API calls etc
★ 1.7kmerlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
★ 5.6kpxethiefy. Python
★ 89Certify. Active Directory certificate abuse.
★ 2ksccmhunter. SCCMHunter is a post-ex tool built to streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domain.
★ 933SMBLibrary. Free, Open Source, User-Mode SMB 1.0/CIFS, SMB 2.0, SMB 2.1 and SMB 3.0 server and client library
★ 876nt5src. Source code of Windows XP (NT5). Leaks are not from me. I just extracted the archive and cabinet files.
★ 1.4kBloodHound. Six Degrees of Domain Admin
★ 3.3kAADInternals. AADInternals PowerShell module for administering Azure AD and Office 365
★ 1.7kdnSpy. Unofficial revival of the well known .NET debugger and assembly editor, dnSpy
★ 11kActive-Directory-Spotlights. PowerShell
★ 42PXEThief. PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
★ 434adidnsdump. Active Directory Integrated DNS dumping by any authenticated user
★ 1.2kAutomatedLab. AutomatedLab is a provisioning solution and framework that lets you deploy complex labs on HyperV and Azure with simple PowerShell scripts. It supports all Windows operating systems from 2008 R2 to 2022, some Linux distributions and various products like AD, Exchange, PKI, IIS, etc.
★ 2.2kCrucibleC2. A C# Command & Control framework
★ 1kBlackbone. Windows memory hacking library
★ 5.5kwindbg-cheat-sheet. My personal cheat sheet for using WinDbg for kernel debugging
★ 474SilkETW. C#
★ 852sliver. Adversary Emulation Framework
★ 12kPipeViewer. A tool that shows detailed information about named pipes in Windows
★ 750krabsetw. KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
★ 792Coercer. A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
★ 2.3kCrassus. C#
★ 633RPCMon. RPC Monitor tool based on Event Tracing for Windows
★ 407sccmwtf. Python
★ 166InterProcessCommunication-Samples. Some Code Samples for Windows based Inter-Process-Communication (IPC)
★ 213windows-coerced-authentication-methods. A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.
★ 600ROADtools. A collection of Azure AD/Entra tools for offensive and defensive security purposes
★ 2.7kflare-wmi. C++
★ 435SharpHandler. C#
★ 188SysWhispers3. SysWhispers on Steroids - AV/EDR evasion via direct system calls.
★ 1.6kElusiveMice. Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
★ 492BokuLoader. A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
★ 1.4kShellcodeFluctuation. An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents
★ 1.1kysoserial.net. Deserialization payload generator for a variety of .NET formatters
★ 3.8kysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
★ 9kdnMerge. A lightweight .NET assembly dependency merger that uses dnLib and 7zip's LZMA SDK for compressing dependant assemblies.
★ 108Certipy. Tool for Active Directory Certificate Services enumeration and abuse
★ 3.6kLdapSignCheck. Beacon Object File & C# project to check LDAP signing
★ 202ADExplorerSnapshot. ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-object dumping to NDJSON.
★ 1.1kSharpSCCM. A C# utility for interacting with SCCM
★ 701dnlib. Reads and writes .NET assemblies and modules
★ 2.5kConfigMgr. Microsoft Endpoint Configuration Manager scripts and tools
★ 651LdapRelayScan. Check for LDAP protections regarding the relay of NTLM authentication
★ 531noPac. CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
★ 1.4kWindows-APT-Warfare. 著作《Windows APT Warfare:惡意程式前線戰術指南》各章節技術實作之原始碼內容
★ 420KrbRelay. Framework for Kerberos relaying
★ 952WinDbg-Samples. Sample extensions, scripts, and API uses for WinDbg.
★ 820Advanced-Process-Injection-Workshop. C++
★ 786infosec-presentations. A repository of previous info-sec presentations I've presented.
★ 166MSRPC-to-ATTACK. A repository that maps commonly used attacks using MSRPC protocols to ATT&CK
★ 349Random. Assorted scripts and one off things
★ 273Powermad. PowerShell MachineAccountQuota and DNS exploit tools
★ 1.5kstats. macOS system monitor in your menu bar
★ 41krpcfirewall. C++
★ 548Win10SysProgBookSamples. Windows 10 System Programming book samples
★ 455SharpAdidnsdump. c# implementation of Active Directory Integrated DNS dumping (authenticated user)
★ 206KernelObjectView. View handles and object for each object type
★ 67syllabi.
★ 64WebclientServiceScanner. Python tool to Check running WebClient services on multiple targets based on @leechristensen
★ 295PKINITtools. Tools for Kerberos PKINIT and relaying to AD CS
★ 914GetWebDAVStatus. Determine if the WebClient Service (WebDAV) is running on a remote system
★ 28gitignore. A collection of useful .gitignore templates
★ 175kMalwareSourceCode. Collection of malware source code for a variety of platforms in an array of different programming languages.
★ 19kkekeo. A little toolbox to play with Microsoft Kerberos in C
★ 1.5kPetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
★ 2.3kpe-sieve. Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
★ 3.8kawesome-linux-rootkits. a summary of linux rootkits published on GitHub
★ 196Hyper-V-Internals. Internals information about Hyper-V
★ 744volatility3. Volatility 3.0 development
★ 4.3killustrated-tls13. The Illustrated TLS 1.3 Connection: Every byte explained
★ 912NoMSBuild. MSBuild without MSbuild.exe
★ 135SigFlip. SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.
★ 1.3kPortBender. TCP Port Redirection Utility
★ 786DivertTCPconn. A TCP packet diverter for Windows platform
★ 346reactos. A free Windows-compatible Operating System
★ 18kWMIReg. PoC to interact with local/remote registry hives through WMI
★ 90SharpSphere. .NET Project for Attacking vCenter
★ 559Legacy-AzureHound.ps1. PowerShell
★ 150SharpHide. Tool to create hidden registry keys.
★ 489DInvoke. Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.
★ 790MicrosoftWontFixList. A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
★ 952ExploitDotNetDCOM. A tool to exploit .NET DCOM for EoP and RCE. Is fixed in latest versions of the .NET.
★ 92StandIn. StandIn is a small .NET35/45 AD post-exploitation toolkit
★ 257DSInternals. Directory Services Internals (DSInternals) PowerShell Module and Framework
★ 2kWhisker. Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
★ 951osed-scripts. bespoke tooling for offensive security's Windows Usermode Exploit Dev course (OSED)
★ 622awesome-cheatsheets. 👩💻👨💻 Awesome cheatsheets for popular programming languages, frameworks and development tools. They include everything you should know in one single file.
★ 46kSysWhispers2. AV/EDR evasion via direct system calls.
★ 1.8kWindowsInternals. Yet another windows internals repo
★ 221charlotte. c++ fully undetected shellcode launcher ;)
★ 976modern-cpp-tutorial. 📚 Modern C++ Tutorial: C++11 to C++26 On the Fly | https://changkun.de/modern-cpp/
★ 26kdefcon_27_windbg_workshop. DEFCON 27 workshop - Modern Debugging with WinDbg Preview
★ 748defcon27_csharp_workshop. Writing custom backdoor payloads with C# - Defcon 27 Workshop
★ 1.2kGhostBuild. GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects
★ 252WhatWeb. Next generation web scanner
★ 6.7kacCOMplice. Tools for discovery and abuse of COM hijacks
★ 339C-Reverse-Shell. a simple c++ reverse shell for windows
★ 116COMProxy. PoC for proxying COM objects when hijacking
★ 217BadBlood. BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.
★ 2.3kvulnerable-AD. Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
★ 2.3kBlacksmith. Building environments to replicate small networks and deploy applications
★ 335Mystikal. macOS Initial Access Payload Generator
★ 326NtCall64. Windows NT x64 syscall fuzzer
★ 641jenkins-attack-framework. Python
★ 577awesome-incident-response. A curated list of tools for incident response
★ 9.3kPPLdump. Dump the memory of a PPL with a userland exploit
★ 893LAPSToolkit. Tool to audit and attack LAPS environments
★ 951StandIn. StandIn is a small .NET35/45 AD post-exploitation toolkit
★ 865p0wnedShell. PowerShell Runspace Post Exploitation Toolkit
★ 1.6kSCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
★ 1.6kHostRecon. This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.
★ 465GadgetToJScript. A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
★ 1.1kNamedPipePTH. Pass the Hash to a named pipe for token Impersonation
★ 145krbrelayx. Kerberos relaying and unconstrained delegation abuse toolkit
★ 1.6kESC. Evil SQL Client (ESC) is an interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration features. While ESC can be a handy SQL Client for daily tasks, it was originally designed for targeting SQL Servers during penetration tests and red team engagements. The intent of the project is to provide an .exe, but also sample files for execution through mediums like msbuild and PowerShell.
★ 304DAFT. DAFT: Database Audit Framework & Toolkit
★ 184RdpThief. Extracting Clear Text Passwords from mstsc.exe using API Hooking.
★ 1.5kblackhat-python3. Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards and refactored to eliminate dependency issues involving the implementation of deprecated libraries.
★ 2.4kJXA-Cookbook. Cookbook for JavaScript for Automation in Mac OS X Yosemite
★ 3kHealthInspector. JXA situational awareness helper by simply reading specific files on a filesystem
★ 82cliProxy. Proxy Unix applications in the terminal
★ 117ghidra_scripts. Ghidra scripts such as a RC4 decrypter, Yara search, stack string decoder, etc.
★ 161ghidra-data. Supporting Data Archives for Ghidra
★ 300phishcatch. A browser extension and API server for detecting corporate password use on external websites
★ 97Reverse-Engineering. A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.
★ 14kat-ps. Adversary Tactics - PowerShell Training
★ 1.6kEvilClippy. A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
★ 2.2koletools. oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
★ 3.4kDidierStevensSuite. Please no pull requests for this repository. Thanks!
★ 2.5kViperMonkey. A VBA parser and emulation engine to analyze malicious macros.
★ 1.1kSecurity-Datasets. Re-play Security Events
★ 1.8kkernel-fuzzer-for-xen-project. Kernel Fuzzer for Xen Project (KF/x) - Hypervisor-based fuzzing using Xen VM forking, VMI & AFL
★ 473gobuster. Directory/File, DNS and VHost busting tool written in Go
★ 14kConfuserEx. An open-source, free protector for .NET applications
★ 3.8kBOF.NET. A .NET Runtime for Cobalt Strike's Beacon Object Files
★ 785SharpSniper. Find specific users in active directory via their username and logon IP address
★ 386DotNetToJScript. A tool to create a JScript file which loads a .NET v2 assembly from memory.
★ 1.3kSysmonCommunityGuide. TrustedSec Sysinternals Sysmon Community Guide
★ 1.4kSharpWMI. SharpWMI is a C# implementation of various WMI functionality.
★ 766awesome-windows-kernel-security-development. windows kernel security development
★ 2.1kawesome-python. An opinionated list of Python frameworks, libraries, tools, and resources
★ 311kdnSpy. .NET debugger and assembly editor
★ 30kpdfs. Technically-oriented PDF Collection (Papers, Specs, Decks, Manuals, etc)
★ 10kinside-com. CD-ROM contents accompanying Dale Rogerson's Inside COM book.
★ 22windows-nt-file-system-internals-book. Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.
★ 20SharpDPAPI. SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
★ 1.4kPowerUpSQL. PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server
★ 2.7kbyeintegrity7-uac. C++
★ 11Awesome-CobaltStrike-Defence. Defences against Cobalt Strike
★ 1.3kPowerForensics. PowerForensics provides an all in one platform for live disk forensic analysis
★ 1.4kExperienced-Pentester-OSEP.
★ 435ShellcodeWrapper. Shellcode wrapper with encryption for multiple target languages
★ 440PEzor. Open-Source Shellcode & PE Packer
★ 2.1kgithub1s. One second to read GitHub code with VS Code.
★ 23kResponder. Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
★ 6.5kBOFs. Collection of Beacon Object Files
★ 638endgame. An AWS Pentesting tool that lets you use one-liner commands to backdoor an AWS account's resources with a rogue AWS account - or share the resources with the entire internet 😈
★ 17SharpGPOAbuse. SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
★ 1.3kSharpHound3. C# Data Collector for the BloodHound Project, Version 3
★ 556BloodHound-Tools. Miscellaneous tools for BloodHound
★ 407ElevateKit. The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.
★ 931injection. C++
★ 830flare-ida. IDA Pro utilities from FLARE team
★ 2.5kwindows-operating-system-archaeology. windows-operating-system-archaeology @Enigma0x3 @subTee
★ 50SharpStay. .NET project for installing Persistence
★ 497