Reims, France

Processus

Elite
@ProcessusT

Ingénieur sécurité 💻 Speaker @LeHack & @DFIR212

HEKATOMB. Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them.

524

Venoma. Yet another C++ Cobalt Strike beacon dropper with Compile-Time API hashing and custom indirect syscalls execution

202

ETWMonitor. Windows notifier tool that detects suspicious connections by monitoring ETW event logs

124

Dictofuscation. Obfuscate the bytes of your payload with an association dictionary

78

UnhookingDLL. This script is used to bypass DLL Hooking using a fresh mapped copy of ntdll file, patch the ETW and trigger a shellcode with process hollowing

74

PsNotifRoutineUnloader. This script is used to unload PsSetCreateProcessNotifyRoutineEx, PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine and PsSetCreateThreadNotifyRoutine from ESET Security to bypass the driver detection

63

LoadThat-PEandAssembly. 2 PE Loader tools that load a PE from memory, decrypt it and make some magic things to execute seamlessly from memory

54

SharpVenoma. CSharp reimplementation of Venoma, another C++ Cobalt Strike beacon dropper with custom indirect syscalls execution

51

HavocHub. PoC for a Havoc agent/handler setup with all C2 traffic routed through GitHub. No direct connections: all commands and responses are relayed through Issues and Comments for maximum stealth.

46

vulnspy. VULNSPY regularly retrieves the latest alerts published by the CERT-FR and the related vulnerabilities with their CVSS score and allows you to notify by email or by discord if a defined threshold is exceeded

38

VolchockC2. VolchockC2 is a custom-built Command & Control (C2) framework, currently under active development. Designed for red team operations and adversary simulation, VolchockC2 focuses on flexibility, stealth, and efficient post-exploitation capabilities.

35

Bypass-AV-DirectSyscalls. Scripts permettant de contourner la protection antivirale de Windows Defender via la technique de Direct Syscalls avec une injection de shellcode préalablement obfusqué avec un fonction XOR.

31

CobaltStrikeBypassDefender. A launcher to load a DLL with xored cobalt strike shellcode executed in memory through process hollowing technique

29

MasterKeyBrute. Bruteforce DPAPI encrypted MasterKey File from Windows Credentials Manager

23

EnumSSN. Enumerate SSN (System Service Numbers or Syscall ID) and syscall instruction address in ntdll module by parsing the PEB of the current process

22

RemClip. RemClip is a C# project which permits to steal user clipboard data and send it to a remote web server under attacker control

15

Automated-C2. Automate your C2 creation with Azure Frontdoor and randomly generated options

15

PayloadDropper. Un dropper de payload indétectable qui désactive l'antivirus Windows Defender puis paramètre un fichier batch à l'ouverture de session de l'utilisateur courant pour télécharger netcat et initier une connexion de type reverse shell vers un serveur C2.

13

Processus-APK. L'application officielle des Tutos de Processus

13

ProcBinder. Un simple client-serveur avec connexions gérées via Socket. Le client est écrit en C et le serveur en Python. J'ai commencé ce projet pour approfondir mes (très faibles) bases en C, soyez indulgents ! :)

12

La-Gamelle. Tous les trucs utilisés dans les Tutos, les shellcodes, les templates, les notes...

12

Reverse_Shell_UDP. Un simple reverse shell indétectable (1/65 sur virustotal au 12/02/2022) écrit en C# qui utilise un client socket UDP sur le port 53 (port DNS) Ce script a été développé pour être utilisé sur le lab professionnel Rastalabs sur la plateforme HackTheBox et n'est pas prévu pour une utilisation différente.

12

DetectEsetHooks. Tool to enumerate ESET hooked functions by parsing the ebehmoni.dll module

9

MikNet. Autonomous red team implementation allowing sound capture and broadcast through an untraceable front-end server to the attacker's station

8

Bypass-AV-ProcessHollowing. Scripts permettant de contourner la protection antivirale de Windows Defender via la technique de Process Hollowing avec une injection de shellcode préalablement obfusqué avec un fonction XOR.

7

OVH_Public_Cloud_-_POST_INSTALLATION_SCRIPT. OVH_Public_Cloud_-_POST_INSTALLATION_SCRIPT

7

DPAPI_reverter. Packer en Powershell qui permet de déchiffrer les identifiants enregistrés dans le gestionnaire d'identifications de Windows grâce à l'outil Mimikatz

6

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

4

Scanner-Powershell. Script Powershell pour récupérer les infos de base d'un poste Windows et les récupérer par email.

4

IndirectSyscalls. A custom reimplementation of indirect syscalls without the use of GetModuleHandleA and GetProcAddress

4

hacktricks. Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

3

aspyco. Aspyco is a python script that permits to upload a local binary through SMB on a remote host. Then it remotely connects to svcctl named pipe through DCERPC to create and start the binary as a service.

3

Python-SSH-Bruteforcer. Script python3 qui permet de scanner toutes les adresses publiques d'internet et de démarrer une session de bruteforce si le port 22 est ouvert

3

CTF-HACKSECUREIMS-2022. Les challenges que j'ai fais pour le CTF de la HackSécuReims 2022

3

Image-comparer. Script de comparaison d'images en python

3

nmapAutomator. A script that you can run in the background!

3

pypykatz. Mimikatz implementation in pure Python

3

CodeCaveInjection. Test d'injection de shellcode dans un fichier PE 64bits

2

ESEDHOUND. ESEDHOUND is a python script that extract datatable from the ntds.dit file to retrieve users, computers and groups. The goal is to send all the infos into Bloodhound to help incident responders for identifying AD objects.

2

invit-bomber. Script python permettant d'envoyer en masse des invitations sur LinkedIn

2

Minou. Bot Discord écrit pour python3

2

list_connexions. liste les dernières ouverture/fermeture de sessions depuis le gestionnaire d'évènements Windows

2

Exploitation-Buffer-Overflow-Windows-32-bits-. Python

2

Hashdump. Un simple exécutable pour récupérer les hashs de la table SAM sous Windows

2

Kernel-Shell. Un simple module qui permet d'exécuter une commande depuis le Kernel dans le Userland

2

AD-USERS-ENUM. Enumerate all users and their SID from LDAP

2

RedTeaming-Tactics-and-Techniques. Red Teaming Tactics and Techniques

1

Shellcode-Encryption. Encrypting shellcode to Bypass AV

1

Havoc. The Havoc Framework

1

AuthenticationPassthroughExploitation. Another example of Azure AD Authentication Passthrough exploitation to intercept LogonUserW API calls

1

whistler. Un simple code en C# pour monter le volume de tous les périphériques audio à fond et émettre un bip puis afficher un gentil message

1

MacFilterExecution. Un simple script C qui permet de lancer un script bash contenu dans une partition chiffrée avec LUKS.

1

Crowdsec_to_MISP. Simple Python script to extract suspicious IPs from Crowdsec sqlite database and inject them into your MISP

1

Araneus. Je sais pas trop encore, on verra

1

ProcBinder-FullPython. Un client-serveur via socket entièrement écrit en Python3

1
55
Apply