Malicious Registry Timestamp Manipulation Technique: Detecting Registry Timestomping
Hacking
grimresource.msc · GitHub
grimresource.msc · GitHub
sokaRepo/CoercedPotatoRDLL: Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege
Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege - sokaRepo/CoercedPotatoRDLL
Getting SYSTEM – Decoder's Blog
In your red teaming or pentesting activities escalating to SYSTEM on a Windows box is always the desired objective. The SYSTEM user is a special operating system user with the highest privilege, m…
Diverto/IPPrintC2: PoC for using MS Windows printers for persistence / command and control via Internet Printing
PoC for using MS Windows printers for persistence / command and control via Internet Printing - Diverto/IPPrintC2
fortra/nanodump: The swiss army knife of LSASS dumping
The swiss army knife of LSASS dumping. Contribute to fortra/nanodump development by creating an account on GitHub.
jstrosch/sclauncher: A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files from shellcode.
A small program written in C that is designed to load 32/64-bit shellcode and allow for execution or debugging. Can also output PE files from shellcode. - jstrosch/sclauncher
marcosValle/awesome-windows-red-team: A curated list of awesome Windows frameworks, libraries, software and resources for Red Teams
A curated list of awesome Windows frameworks, libraries, software and resources for Red Teams - GitHub - marcosValle/awesome-windows-red-team: A curated list of awesome Windows frameworks, librari...
hackvens/CoercedPotato
Contribute to hackvens/CoercedPotato development by creating an account on GitHub.
GitHub - GoSecure/pyrdp: RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact - GitHub - GoSecure/pyrdp: RDP monster-in-the-middle (mitm) and library for Pyth...
Rpc toolkit fantastic interfaces how to find
GitHub - D1rkMtr/RecyclePersist: implementation of Persistence via Recycle Bin by adding "open\command" subkey to the "HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell" key and changing its value to the implant path
implementation of Persistence via Recycle Bin by adding "open\command" subkey to the "HKCR\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shell" key and changing i...
Hijack Libs
GitHub - hfiref0x/UACME: Defeating Windows User Account Control
Defeating Windows User Account Control. Contribute to hfiref0x/UACME development by creating an account on GitHub.
Yet another sdclt UAC bypass - Sevagas
Fileless UAC bypass via COM hijack using sdtlc.exe auto-elevated process.
GitHub - mandiant/ADFSpoof
Contribute to mandiant/ADFSpoof development by creating an account on GitHub.
GitHub - helpsystems/nanodump: A crappy LSASS dumper with no ASCII art
A crappy LSASS dumper with no ASCII art. Contribute to helpsystems/nanodump development by creating an account on GitHub.
GitHub - S1ckB0y1337/TokenPlayer: Manipulating and Abusing Windows Access Tokens.
Manipulating and Abusing Windows Access Tokens. Contribute to S1ckB0y1337/TokenPlayer development by creating an account on GitHub.
GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A list of useful payloads and bypass for Web Application Security and Pentest/CTF - GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and ...
GitHub - antonioCoco/RemotePotato0: Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin.
Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin. - GitHub - antonioCoco/RemotePotato0: Just another "Won't Fix" W...
GitHub - M2Team/NSudo: Series of System Administration Tools
Series of System Administration Tools. Contribute to M2Team/NSudo development by creating an account on GitHub.
LOLBAS
GitHub - bytecode77/r77-rootkit: Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc. - GitHub - bytecode77/r77-rootkit: Fileless ring 3 rootkit with installer and persisten...
Update for Microsoft Defender antimalware platform (KB4052623)
Has command for reverting signatures. Useful to downgrade or remove signatures to allow Defender to run but be unable to detect anything.
Defender Module
Use this topic to help manage Windows and Windows Server technologies with Windows PowerShell.
VBScript - Creating a Shortcut
pylnk3
Windows LNK File Parser and Creator
GitHub - GhostPack/Rubeus: Trying to tame the three-headed dog.
Trying to tame the three-headed dog. Contribute to GhostPack/Rubeus development by creating an account on GitHub.
GitHub - gentilkiwi/mimikatz: A little tool to play with Windows security
A little tool to play with Windows security. Contribute to gentilkiwi/mimikatz development by creating an account on GitHub.