khr0x40sh

Expert
@khr0x40sh

MacroShop. Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

408

WhiteListEvasion. Collection of scripts, binaries and the like to aid in WhiteList Evasion on a Microsoft Windows Network.

128

Galvatron. Powershell fork of Monohard by Carlos Ganoza P. This botnet/backdoor was designed to egress over unecrypted web using very little, but effective obfuscation. Egress over ICMP and DNS are planned as features. Lastly, the server code is designed to setup the C2 on a LAMP-esque server. The default creds are admin/admin.

40

metasploit-modules. Ruby

36

PowerW0rm. PowerShell

16

PowerSurfer. A powershell based traffic generation scripts to simulate user activity via Internet Explorer

15

ms16-032. C

9

ms16_032_DLL. DLL of MS16-032 Exploit

6

malwareanalysis. snippets related to malware analysis

3

Mockingjay. Tests and implementation of Mockingjay technique

3

SharpMockingJay. C# / .NET implementation of the local DLL Injection use case of the MockingJay EDR Bypass technique

3

LNKfun. A simple LNK file parser/editor written in PS1.

3

SharpeningCobaltStrike. in realtime v35/40 dotnet compiler for your linux Cobalt Strike C2. New fresh compiled and obfuscated binary for each use

3

OSCP-2. Collection of things made during my OSCP journey

3

talks. Files From Talks

2

win-brute-logon. Crack any Microsoft Windows users password without any privilege (Guest account included)

1

CVE-2024-4956. CVE-2024-4956 Python exploitation utility

1

Minimalistic-offensive-security-tools. A repository of tools for pentesting of restricted and isolated environments.

1

embedps. C#

1

Cobalt-Strike-Aggressor-Scripts. Cobalt Strike Aggressor 插件包

1

DueDLLigence. C#

1

Sandboxescaperclone. Reuploading the code she removed.

1

AmsiScanBufferBypass. C#

1

SharpRDP. Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

1

sharpratworm. Automatically exported from code.google.com/p/sharpratworm

1

Egress-Assess. Egress-Assess is a tool used to test egress data detection capabilities

1

Aggressor-scripts. Aggressor scripts I've made for Cobalt Strike

1

MS17-010. MS17-010

1

CVE-2018-4878. ActionScript

1

Salsa-tools. Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

1

kismetearth-net. Automatically exported from code.google.com/p/kismetearth-net

1

EvilNetConnectionWMIProvider. C#

1

DefenderCheck. Identifies the bytes that Microsoft Defender flags on.

1

SharpSploit. SharpSploit is a .NET post-exploitation library written in C#

1

NetLoader. Loads any C# binary in mem, patching AMSI and bypassing Windows Defender

1

DumpsterFire. "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

1
36
Apply