Doing stuff with stuff
AggressorCollection. Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors
152C2Kv2. Updated version of C2K
50PreludeOperator_QuickCheck. Simple Powershell Prelude Operator Quick Check
8universal-syscall-64. Resolve syscall numbers at runtime for all Windows versions.
4LockdExeDemo. A demo of the relevant blog post: https://www.arashparsa.com/hook-heaps-and-live-free/
4BSidesTO2017. Slides and demo content from our BSidesTO 2017 presentation.
3AlternativeShellcodeExec. Alternative Shellcode Execution Via Callbacks
2DC416October. Examples used in the October DC416 meetup
2uefi-ntfs. UEFI:NTFS - Boot NTFS or exFAT partitions from UEFI
1Smug_Fu3k. C++
1mitmproxy2swagger. Automagically reverse-engineer REST APIs via capturing traffic
1C2-Tool-Collection. A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
1Osiris-Sourcecode. Alleged source code leak of Osiris banking trojan
1Penetration-Testing-Tools. A collection of more than 170+ tools, scripts, cheatsheets and other loots that I have developed over years for Red Teaming/Pentesting/IT Security audits purposes. Most of them came handy on at least one of my real-world engagements.
1GoodHound. Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.
1AsmHalosGate. x64 Assembly HalosGate direct System Caller to evade EDR UserLand hooks
1EopMon. Elevation of privilege detector based on HyperPlatform
1ChromeTools. A collection of tools to abuse chrome browser
1Hook_API. Assembly block for hooking windows API functions.
1EfiGuard. Disable PatchGuard and DSE at boot time
1ReflectiveDLLRefresher. Universal Unhooking
1KaynLdr. KaynLdr is a Reflective Loader written in C/ASM
1DefenderSwitch. Stop Windows Defender using the Win32 API
1Windows-API-Hashing. This is a simple example and explanation of obfuscating API resolution via hashing
1RemoteWriteMonitor. A tool to help malware analysts tell that the sample is injecting code into other process.
1delete2SYSTEM. Weaponizing for Arbitrary Files/Directories Delete bugs to Get NT AUTHORITY\SYSTEM
1Nobelium-PdfDLRunAesShellcode. A recreation of the "Nobelium" malware based on Microsofts Malware analysis - Part 1: PDF2Pwn
1XOREncryption. XOR encryption implementations for several languages.
1cypheroth. Automated, extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.
1PR0CESS. some gadgets about windows process and ready to use :)
1Mapping-Injection. Just another Windows Process Injection
1Eventlogedit-evtx--Evolution. Remove individual lines from Windows XML Event Log (EVTX) files
1brown-bags. C#
1SyscallAmsiScanBufferBypass. AmsiScanBufferBypass using D/Invoke
1BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW.
1EDRs. C
1PrivFu. Kernel mode WinDbg extension and PoCs for token privilege investigation.
1TitanLdr. Titan: A crappy Reflective Loader written in C and assembly for Cobalt Strike. Redirects DNS Beacon over DoH
1Shark. Turn off PatchGuard in real time for win7 (7600) ~ later
1mal_unpack. Dynamic unpacker based on PE-sieve
1SharpNamedPipePTH. Pass the Hash to a named pipe for token Impersonation
1BeaconEye. Hunts out CobaltStrike beacons and logs operator command output
1SharpNoPSExec. Get file less command execution for lateral movement.
1building-c2-implants-in-cpp. The source code files that accompany the short book "Building C2 Implants in C++: A Primer" by Steven Patterson (@shogunlab).
1CSharpMusings. Collection of random C# tooling
1GRAT2. We developed GRAT2 Command & Control (C2) project for learning purpose.
1Sealighter. Sysmon-Like research tool for ETW
1RunPE-In-Memory. Run a Exe File (PE Module) in memory (like an Application Loader)
1GadgetToJScript. A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
1InfinityHook. Hook system calls, context switches, page faults and more.
1luckystrike. A PowerShell based utility for the creation of malicious Office macro documents.
1Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.
1Zolom. C# Executable with embedded Python that can be used reflectively to run python code on systems without Python installed
1ColdHook. A simple open source memory hooking library for Windows x86/x64
1DefensiveInjector. C
1CobaltStrike-ToolKit. Some useful scripts for CobaltStrike
1NTHASH-FPC. Pascal
1