Toronto

InvokeThreatGuy

Advanced
@invokethreatguy

Doing stuff with stuff

AggressorCollection. Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors

152

C2Kv2. Updated version of C2K

50

PreludeOperator_QuickCheck. Simple Powershell Prelude Operator Quick Check

8

universal-syscall-64. Resolve syscall numbers at runtime for all Windows versions.

4

LockdExeDemo. A demo of the relevant blog post: https://www.arashparsa.com/hook-heaps-and-live-free/

4

BSidesTO2017. Slides and demo content from our BSidesTO 2017 presentation.

3

AlternativeShellcodeExec. Alternative Shellcode Execution Via Callbacks

2

DC416October. Examples used in the October DC416 meetup

2

uefi-ntfs. UEFI:NTFS - Boot NTFS or exFAT partitions from UEFI

1

Smug_Fu3k. C++

1

mitmproxy2swagger. Automagically reverse-engineer REST APIs via capturing traffic

1

C2-Tool-Collection. A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

1

Osiris-Sourcecode. Alleged source code leak of Osiris banking trojan

1

Penetration-Testing-Tools. A collection of more than 170+ tools, scripts, cheatsheets and other loots that I have developed over years for Red Teaming/Pentesting/IT Security audits purposes. Most of them came handy on at least one of my real-world engagements.

1

GoodHound. Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

1

AsmHalosGate. x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks

1

EopMon. Elevation of privilege detector based on HyperPlatform

1

ChromeTools. A collection of tools to abuse chrome browser

1

Hook_API. Assembly block for hooking windows API functions.

1

EfiGuard. Disable PatchGuard and DSE at boot time

1

ReflectiveDLLRefresher. Universal Unhooking

1

KaynLdr. KaynLdr is a Reflective Loader written in C/ASM

1

DefenderSwitch. Stop Windows Defender using the Win32 API

1

Windows-API-Hashing. This is a simple example and explanation of obfuscating API resolution via hashing

1

RemoteWriteMonitor. A tool to help malware analysts tell that the sample is injecting code into other process.

1

delete2SYSTEM. Weaponizing for Arbitrary Files/Directories Delete bugs to Get NT AUTHORITY\SYSTEM

1

Nobelium-PdfDLRunAesShellcode. A recreation of the "Nobelium" malware based on Microsofts Malware analysis - Part 1: PDF2Pwn

1

XOREncryption. XOR encryption implementations for several languages.

1

cypheroth. Automated, extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.

1

PR0CESS. some gadgets about windows process and ready to use :)

1

Mapping-Injection. Just another Windows Process Injection

1

Eventlogedit-evtx--Evolution. Remove individual lines from Windows XML Event Log (EVTX) files

1

brown-bags. C#

1

SyscallAmsiScanBufferBypass. AmsiScanBufferBypass using D/Invoke

1

BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW.

1

EDRs. C

1

PrivFu. Kernel mode WinDbg extension and PoCs for token privilege investigation.

1

TitanLdr. Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH

1

Shark. Turn off PatchGuard in real time for win7 (7600) ~ later

1

mal_unpack. Dynamic unpacker based on PE-sieve

1

SharpNamedPipePTH. Pass the Hash to a named pipe for token Impersonation

1

BeaconEye. Hunts out CobaltStrike beacons and logs operator command output

1

SharpNoPSExec. Get file less command execution for lateral movement.

1

building-c2-implants-in-cpp. The source code files that accompany the short book "Building C2 Implants in C++: A Primer" by Steven Patterson (@shogunlab).

1

CSharpMusings. Collection of random C# tooling

1

GRAT2. We developed GRAT2 Command & Control (C2) project for learning purpose.

1

Sealighter. Sysmon-Like research tool for ETW

1

RunPE-In-Memory. Run a Exe File (PE Module) in memory (like an Application Loader)

1

GadgetToJScript. A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.

1

InfinityHook. Hook system calls, context switches, page faults and more.

1

luckystrike. A PowerShell based utility for the creation of malicious Office macro documents.

1

Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.

1

Zolom. C# Executable with embedded Python that can be used reflectively to run python code on systems without Python installed

1

ColdHook. A simple open source memory hooking library for Windows x86/x64

1

DefensiveInjector. C

1

CobaltStrike-ToolKit. Some useful scripts for CobaltStrike

1

NTHASH-FPC. Pascal

1
57
Apply