This is your work, valued

tothi

Elite
@tothi

rbcd-attack. Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket

645

dll-hijack-by-proxying. Exploiting DLL Hijacking by DLL Proxying Super Easily

563

pwn-hisilicon-dvr. Python

384

ad-honeypot-autodeploy. Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

259

serviceDetector. Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

241

usbgadget-tool. Dumb USB HID gadget creator for Android (for triggering device driver install on Windows for LPE)

150

stager_libpeconv. A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading

85

smbmap. SMBMap is a handy SMB enumeration tool - here with Kerberos support

73

SharpStay. .NET project for installing Persistence

63

hs-dvr-telnet. open telnet port on modern HiSilicon devices

56

log4shell-vulnerable-app. A Basic Java Application Vulnerable to the Log4Shell RCE

41

PowerLessShell. Run PowerShell command without invoking powershell.exe

36

CVE-2021-1675. C# and Impacket implementation (here with Kerberos auth support) of PrintNightmare CVE-2021-1675/CVE-2021-34527

29

ctfs. some example ctf writeups

27

azure-function-proxy. basic proxy as an azure function serverless app

17

PetitPotam. PetitPotam fork with Kerberos support in the impacket script

17

linkedin-auth-bypass. browse linkedin profiles without a registered account

15

kali-rpi-luks-crypt. Full disk encryption for Kali on Raspberry using LUKS

15

malicious-service. Minimal Windows Service Template for demonstrating privilege escalation via weak service executable permissions

14

impacket. Impacket is a collection of Python classes for working with network protocols.

13

smtp2slack4qnap. Compact SMTP to HTTP Gateway (targeting Slack for QNAP-NAS notifications)

12

NoteThief. Grab unsaved Notepad contents with a Beacon Object File

11

malicious-hisilicon-scripts. Materials from my older (2018) HiSilicon research

10

Bundesnachrichtendienst. reversing / malware analysis recruitment challenge for German Federal Intelligence

8

SharpShot. Trivial .NET desktop capturing for Red Team operations

6

issuu-dl. download pdf from issuu.com

6

gcstar-win32. standalone executable built from GCstar Perl release

5

oauth-mitmproxy. oauth refresh_token client in mitmproxy

5

steganography. Simple C++ Image Steganography tool to encrypt and hide files insde images using Least-Significant-Bit encoding.

5

lineageos-bullhead-build. Unofficial LineageOS builds for Google Nexus 5X "bullhead" devices

5

zphisher. An automated phishing tool with 30+ templates.

5

remotethermo. remotethermo.com API test

4

CVE-2020-1472. Test tool for CVE-2020-1472

3

nmap-http-screenshot. take screenshots of http services from an nmap xml output

3

azure-function-proxy-ng. Azure Function as a Reverse Proxy (e.g. for C2 ;) )

3

railfence. a simple python implementation of the Rail Fence cipher (with offset support)

3

sliver. Adversary Emulation Framework

3

Powershell-PostExploitation. Scripts created to help with post exploitation of a Windows host

2

wifipem. automated tool for extracting RADIUS public certificates from pcap files and live captures

2

burp-Base64PostRequest. Burp Extension: Base64 decode / encode POST request data

2

prosmart-mqtt. Minimal proSmart - MQTT Gateway

2

android-keyboard-gadget. Convert your Android device into USB keyboard/mouse, control your PC from your Android device remotely, including BIOS/bootloader.

2

DeviceGuardBypasses. A repository of some of my Windows 10 Device Guard Bypasses

2

NetLoader. Loads any C# binary in mem, patching AMSI + ETW.

2

riemann-nonconvex. Simulation of a totally asymmetric attractive interacting particle system

2

sencor-bluetooth. Sample development Python scripts for reading data from the Sencor SWS 500 Outdoor Thermo/Humidity Meter Bluetooth LE device.

2

tensorflow-captcha-solver. 🎲 Solve image based captchas using Tensorflow neural networks

1

MsgKit. A .NET library to make MSG files without the need for Outlook

1

adduser. Programmatically create an administrative user under Windows

1

mvt. MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

1

home-assistant-core. :house_with_garden: Open source home automation that puts local control and privacy first.

1

inceptor. Template-Driven AV/EDR Evasion Framework

1

VulnerableDrivers. Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)

1

KrbRelay. Framework for Kerberos relaying

1

sudo-cve-2019-18634. Proof of Concept for CVE-2019-18634

1

rocketchat-history-downloader. Download, export, and preserve Rocket.Chat user-accessible channel logs and history via the Rocket.Chat API. Designed for users who would like to preserve their conversations without having administrative access on a Rocket.Chat server.

1

openvasreporting. OpenVAS Reporting: Convert OpenVAS XML report files to reports

1

SharpSecDump. .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

1

malware-agenttesla. Brief Malware Analysis of an Agent Tesla variant

1

EDRs. C

1