This is your work, valued

Shanghai

Uknow

Elite
@uknowsec

不忘初心,方得始终

Active-Directory-Pentest-Notes. 个人域渗透学习笔记

1.8k

SharpDecryptPwd. 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。源码:https://github.com/RowTeam/SharpDecryptPwd

1.3k

SharpSQLTools. SharpSQLTools 和@Rcoil一起写的小工具,可上传下载文件,xp_cmdshell与sp_oacreate执行命令回显和clr加载程序集执行相应操作。

967

SweetPotato. Modifying SweetPotato to support load shellcode and webshell

794

SharpToolsAggressor. 内网渗透中常用的c#程序整合成cs脚本,直接内存加载。持续更新~

500

frpModify. 修改frp支持域前置与配置文件自删除

400

SharpNetCheck. C#

285

TailorScan. 自用缝合怪内网扫描器,支持端口扫描,识别服务,获取title,扫描多网卡,ms17010扫描,icmp存活探测。

282

Fofa-gui. Fofa采集工具-自修改版本

273

loginlog_windows. 读取登录过本机的登录失败或登录成功的所有计算机信息,在内网渗透中快速定位运维管理人员。

221

SharpEventLog. c# 读取登录过本机的登录失败或登录成功(4624,4625)的所有计算机信息,在内网渗透中快速定位运维管理人员。

210

getSystem. webshell下提权执行命令 Reference:https://github.com/yusufqk/SystemToken

207

SharpSQLDump. 内网渗透中快速获取数据库所有库名,表名,列名。具体判断后再去翻数据,节省时间。适用于mysql,mssql。

198

JuicyPotato. Modifying JuicyPotato to support load shellcode and webshell

197

BurpSuite-Extender-fastjson. Reference:https://www.w2n1ck.com/article/44/

156

keylogger. 键盘记录,支持定时回传

148

SharpCheckInfo. 收集目标主机信息,包括最近打开文件,系统环境变量和回收站文件等等

114

CreateService. 创建服务持久化

109

OXID_Find. OXID_Find by C++(多线程) 通过OXID解析器获取Windows远程主机上网卡地址

91

SharpOSS. Quickly upload files to aliyun OSS by aliyun-oss-csharp-sdk

77

SharpOXID-Find. OXID_Find by Csharp(多线程) 通过OXID解析器获取Windows远程主机上网卡地址 From @RcoIl

56

SharpAVKB. Windows杀软对比和补丁号对比

55

RemoteCryptoShellcodeLoader. DomainFronting(aliyun)远程加载shellcode,远程获取shellcode使用aes动态加密传输数据

48

Frida-Hook-In-Java-Notes. Java层frida hook学习笔记 https://uknowsec.cn

47

SSL. StenographyShellcodeLoader

43

WeChatMsg. 修改https://github.com/LC044/WeChatMsg 实现离线解密展示聊天记录

37

ReflectiveDLLInjection-Notes. ReflectiveDLL学习代码

36

RemoteReflectiveDLL. C++

35

SauronEye-Modify. 在原项目上加上将找到的文件压缩打包上传oss,另外做了部分小修改。

30

SharpZip. C#

28

ProxyPool. 使用小熊ip获取代理ip,配合Gost的WebApi定时更新Gost配置来实现代理池功能。

12

SharpCryptPermute. Crypt/Decrypt Proxyshell Payload

9

ModbusPeachPit. ModbusPeachPit

9

SharpLocker. 钓鱼锁屏界面,并在当前目录下生成log.txt记录密码

6

EfsPotato. Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).

6

uknowsec.

6

List-RDP-Connections-History. agscript-script List-RDP-Connections-History

5

uknowsec.github.io. HTML

4

Detours. Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.

3

gps_map. 服务端server.php接收GPS模块数据进行处理存入数据库,setPoint.php和json.php查询得到数据库GPS数据,index.html通过ajax请求setPoint.php和json.php中的GPS数据通过百度地图API进行显示以及表格形式输出。

3

yzm_captcha. yzm captcha

3

Captchademo. 验证码爆破场景demo

2

unicode-jsp. HTML

2

hub-mirror. 🚀 Docker 镜像代理,通过 GitHub Actions 将 docker.io、gcr.io、registry.k8s.io、k8s.gcr.io、quay.io、ghcr.io 等国外镜像转换为国内镜像加速下载

2

demo.

1

aggressor_scripts. A collection of useful scripts for Cobalt Strike

1

SCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

1

hashcat. World's fastest and most advanced password recovery utility

1

jsq. HTML

1

cpp_code. C++

1

godnslog. An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability

1