0x4143 / adversaryemulation-gems
A not so awesome list of adversary emulation gems for aspiring red/blue/purple teamers
☆14Updated 2 years ago
Alternatives and similar repositories for adversaryemulation-gems:
Users that are interested in adversaryemulation-gems are comparing it to the libraries listed below
- Slides from my talk at the Adversary Village, Defcon 30☆29Updated 2 years ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- WMI SA stuffs☆29Updated 2 years ago
- My experiments in weaponizing Nim (https://nim-lang.org/)☆17Updated last year
- ☆11Updated 4 years ago
- Defeating Anti-Debugging Techniques for Malware Analysis☆13Updated 2 years ago
- Repository for LNK stuff☆29Updated 2 years ago
- A cap/pcap packet parser to make life easier when performing stealth/passive reconnaissance.☆21Updated 7 months ago
- ☆12Updated 2 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Updated 3 years ago
- Tools for playing w/ CobaltStrike config - extractin, detection, processing, etc...☆27Updated last year
- Adapt practically persistence steadiness strategies working at Windows 10 utilized by sponsored nation-state threat actors, as Turla, Pro…☆20Updated 4 years ago
- just manipulatin these here tokens yes sir nothing weird☆22Updated 2 years ago
- PoC MSI payload based on ASEC/AhnLab's blog post☆23Updated 2 years ago
- A custom SentinelOne USB scanner.☆18Updated 2 years ago
- Remote code execution in Power Platform connectors via JSON deserialization☆20Updated last year
- Tools that trigger False Positive AV alerts☆44Updated last month
- A collection of my presentation materials.☆16Updated 9 months ago
- Ransoblin (Ransomware Bokoblin)☆17Updated 4 years ago
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆48Updated last year
- Random scripts for azure stuff☆11Updated 2 years ago
- CSharp4Pentesters☆12Updated 2 years ago
- Work in Progress repo☆14Updated 5 years ago
- Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them b…☆20Updated 10 months ago
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated last year
- Extension functionality for the NightHawk operator client☆26Updated last year
- Python tool to find vulnerable AD object and generating csv report☆14Updated 2 years ago
- ☆12Updated 3 years ago
- Open YARA scan- and search engine☆19Updated 2 months ago
- A tool that adds reproducible UUIDs to YARA rules☆13Updated 9 months ago