curi0usJack

Expert
@curi0usJack

luckystrike. A PowerShell based utility for the creation of malicious Office macro documents.

1.1k

ADImporter. Credit to Helge Klein - https://helgeklein.com/blog/2015/02/creating-realistic-test-user-accounts-active-directory/

69

rubeus2ccache. Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.

67

ansible-redelk. Ansible playbooks for instrumenting a Red Team environment with RedElk

52

activedirectory. This script runs several security checks and makes modifications (with your permission) to your Active Directory domain to improve it's security posture.

45

Ludus-MDE-MDI-Roles. Ludus roles to deploy ASR rules and MDI auditing settings

25

ludus_badblood. Outfits your ludus AD domain with BadBlood info.

17

psfire. simple demo of using C# & System.Management.Automation.dll to run powershell code (b64 encoded) without powershell.exe

14

Ansible-SSH-Conf. Uses Ansible to generate a new EC2 instance then an SSH conf file for that instance.

10

pssync. Powershell Synchronization Repository

9

custompayload. Put output from msfvenom into custom c# project for AV evasion

9

dotfiles. Shell

8

slides.

5

ludus_splunk. A role for installing Splunk Enterprise on a Debian host.

5

ptf. The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

4

autobrute. Simple http/ntlm brute forcer with some helpful options.

4

ludus_splunk_universalforwarder. A role for deploying the Splunk UF to lab hosts.

4

metasploit-framework. Metasploit Framework

3

ansible_arch_vm. Ansible playbook to build and configure an Arch VM

3

dnscat2-powershell. A Powershell port of dnscat2, a DNS covert channel tool.

1

unicorn. Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.

1

vcr-1. Vulnerability Compliance Report Tool used to parse Nessus files into html reports created by SynerComm, Inc.

1

SCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

1

Powermad. PowerShell MachineAccountQuota and DNS exploit tools

1

AndrewSpecial. AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.

1

gimme. A tool for alerting on searches for products you want. Shameless streaming project. xDD

1

ROADtools. The Azure AD exploration framework.

1
27
Apply