@JohnLaTwC Security Fellow and Corporate Vice President, Microsoft Security
Shared. Shared Blogs and Notebooks
499PyPowerShellXray. Python script to decode common encoded PowerShell scripts
216MSRC. Scripts for interacting with MSRC portal data
77Bluehat2018GraphWorkshop. Bluehat 2018 Graphs for Security Workshop
42MacroJob. Proof of concept VBA code to add to Normal.dot to put restrictions on Word
40EvilOSX. A pure python, post-exploitation, RAT (Remote Administration Tool) for macOS / OSX.
10Mandiant-Azure-AD-Investigator. PowerShell
3XLMMacroDeobfuscator. Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)
3Bella. Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻
2pe-sieve. Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
2CustomKeyboardLayoutPersistence. Achieve execution using a custom keyboard layout
2Reports. HTML
2SharpUp. SharpUp is a C# port of various PowerUp functionality.
1SharpC2. Command and Control Framework written in C#.
1EDRSandblast. C
1ocsf-schema. OCSF Schema
1CS-Remote-OPs-BOF. C
1PSBits. Simple (relatively) things allowing you to dig a bit deeper than usual.
1rpcfirewall. C++
1xPipe. Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions
1PPLdump. Dump the memory of a PPL with a userland exploit
1DLL-Hijack-Search-Order-BOF. DLL Hijack Search Order Enumeration BOF
1InlineExecute-Assembly. InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module
1DarkLoadLibrary. LoadLibrary for offensive operations
1LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
1sunburst_countermeasures. YARA
1WDATPAPI. WDATP API Sample
1DidierStevensSuite. Please no pull requests for this repository. Thanks!
1Raccine. A Simple Ransomware Vaccine
1msticpy. Microsoft Threat Intelligence Security Tools
1CCCS-Yara. YARA rule metadata specification and validation utility
1CS-Situational-Awareness-BOF. Situational Awareness commands implemented using Beacon Object Files
1TaskManagerBitmap. Displays a bitmap on Task Manager's CPU activity view. For systems with > 64 CPUs.
1gcat. A PoC backdoor that uses Gmail as a C&C server
1WinRpcFunctions. PowerShell
1Firewall_Walker_BOF. A BOF to interact with COM objects associated with the Windows software firewall.
1RAT-via-Telegram. Windows Remote Administration Tool via Telegram
1signature-base. Signature base for my scanner tools
1metasploit-framework. Metasploit Framework
1CrowdFMS. CrowdStrike Feed Management System
1