Baron samedit heap based overflow sudo
Hacking
GitHub - leonjza/log4jpwn: log4j rce test environment and poc
log4j rce test environment and poc. Contribute to leonjza/log4jpwn development by creating an account on GitHub.
pkexec: local privilege escalation (CVE-2021-4034) (a2bf5c9c) · Commits · polkit / polkit · GitLab
Commit for pwnkit fix
Pwnkit
GitHub - mandiant/ADFSpoof
Contribute to mandiant/ADFSpoof development by creating an account on GitHub.
GitHub - helpsystems/nanodump: A crappy LSASS dumper with no ASCII art
A crappy LSASS dumper with no ASCII art. Contribute to helpsystems/nanodump development by creating an account on GitHub.
GitHub - S1ckB0y1337/TokenPlayer: Manipulating and Abusing Windows Access Tokens.
Manipulating and Abusing Windows Access Tokens. Contribute to S1ckB0y1337/TokenPlayer development by creating an account on GitHub.
Yours Truly, Signed AV Driver: Weaponizing an Antivirus Driver | Aon
As we head into 2022, ransomware groups continue to plague our digital environment with new and interesting techniques to bypass Antivirus (AV) and Endpoint Detection and Response (EDR) solutions and ensuring the successful execution of their ransomware payloads. In December 2021, Stroz Friedberg’s Incident Response Services team engaged in a Digital Forensics and Incident […]
MSDT DLL Hijack UAC bypass - Sevagas
UAC Bypass via DLL hijacking of Microsoft Support Diagnostic Tool (MSDT). The UAC bypass method described here is based on DLL hijacking which happens when loading the Bluetooth diagnostic package.
Offensive Lateral Movement
Lateral movement is the process of moving from one compromised host to another. Penetration testers and red teamers alike commonly used to…
Penetration Testing Explained, Part IV: Making the Lateral Move
You can think about the post-exploitation part of penetration testing as an army or rebel force living off the land. You’re scrounging around the victim’s website using what’s available —...
:: bettercap
GitHub - liamg/traitor: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock - GitHub - liamg/traitor: Automatic Linux pr...
GitHub - firmadyne/firmadyne: Platform for emulation and dynamic analysis of Linux-based firmware
Platform for emulation and dynamic analysis of Linux-based firmware - GitHub - firmadyne/firmadyne: Platform for emulation and dynamic analysis of Linux-based firmware
GitHub - nishitm/wotop: Web on top of any protocol
Web on top of any protocol. Contribute to nishitm/wotop development by creating an account on GitHub.
Container whitepaper
GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A list of useful payloads and bypass for Web Application Security and Pentest/CTF - GitHub - swisskyrepo/PayloadsAllTheThings: A list of useful payloads and bypass for Web Application Security and ...
GitHub - antonioCoco/RemotePotato0: Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin.
Just another "Won't Fix" Windows Privilege Escalation from User to Domain Admin. - GitHub - antonioCoco/RemotePotato0: Just another "Won't Fix" W...
GitHub - M2Team/NSudo: Series of System Administration Tools
Series of System Administration Tools. Contribute to M2Team/NSudo development by creating an account on GitHub.
LOLBAS
GTFOBins
GitHub - huntergregal/mimipenguin: A tool to dump the login password from the current linux user
A tool to dump the login password from the current linux user - GitHub - huntergregal/mimipenguin: A tool to dump the login password from the current linux user
GitHub - m0nad/Diamorphine: LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64) - GitHub - m0nad/Diamorphine: LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
ired.team
My notes about all things red teaming experiments and more.
(Very well done notes, great stuff on red teaming)
GitHub - bytecode77/r77-rootkit: Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc. - GitHub - bytecode77/r77-rootkit: Fileless ring 3 rootkit with installer and persisten...
GitHub - infosecn1nja/Red-Teaming-Toolkit: This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter. - GitHub - infosecn1nja/Red-Teaming-Toolkit: This repository contains cutting-edge open-so...
Community Kit
Cobalt Strike Community Kit
Update for Microsoft Defender antimalware platform (KB4052623)
Has command for reverting signatures. Useful to downgrade or remove signatures to allow Defender to run but be unable to detect anything.
Defender Module
Use this topic to help manage Windows and Windows Server technologies with Windows PowerShell.
VBScript - Creating a Shortcut