3gstudent / Use-msxsl-to-bypass-AppLocker
Learn from Casey Smith@subTee
☆29Updated 4 years ago
Alternatives and similar repositories for Use-msxsl-to-bypass-AppLocker:
Users that are interested in Use-msxsl-to-bypass-AppLocker are comparing it to the libraries listed below
- use COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)☆58Updated 7 years ago
- (Small change to make it easier to test the payload and combine it with SILENTTRINITY.)A tool for generating .NET serialized gadgets that…☆43Updated 5 years ago
- Use powershell to test Office-based persistence methods☆76Updated 4 years ago
- This is a group of tools that I was planning on releasing During Derbycon 2019 talk if it was accepted or with a blogpost if not.☆43Updated 3 years ago
- Sound Research SECOMN service Privilege Escalation (windows 10)☆40Updated 5 years ago
- Use Waitfor.exe to maintain persistence☆54Updated 4 years ago
- Contains poc's and my research works☆31Updated 2 years ago
- Powershell to copy ntds.dit☆62Updated 8 years ago
- POC for Cobalt Strike external C2☆133Updated 3 years ago
- Cobaltstrike Aggressor Scripts☆28Updated 8 years ago
- Aggressor script to integrate Phant0m with Cobalt Strike☆27Updated 7 years ago
- Collect & Optimize awesome CobaltStrike aggressor scripts, hope to create a All-In-One framework.☆37Updated 5 years ago
- Stealing passwords every time they change☆66Updated 5 years ago
- SharpTask is a simple code set to interact with the Task Scheduler service api and is compatible with Cobalt Strike.☆90Updated 4 years ago
- Yet another LSASS dumper☆76Updated 4 years ago
- Standalone version of my AES Powershell payload for Cobalt Strike.☆110Updated 5 years ago
- Python api for usage with cobalt strike's External C2 specification☆62Updated 6 years ago
- Alternative C# Implementation tool to retrieve Active Directory Integrated DNS records with IP addresses☆49Updated 4 years ago
- Aggressor Scripts for Cobalt Strike☆76Updated last year
- Security Support Provider Interface☆46Updated 5 years ago
- Initial Commit of Coresploit☆56Updated 3 years ago
- CVE-2019-1064 Local Privilege Escalation Vulnerability☆24Updated 5 years ago
- PoC to interact with local/remote registry hives through WMI☆85Updated 4 years ago
- ☆36Updated 6 years ago
- Lists of AMSI triggers (VBA, JScript / VBScript)☆33Updated 5 years ago
- a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket☆68Updated 6 years ago
- A quick tool for hiding a new process running shellcode.☆57Updated 4 years ago
- Cobalt Strike Aggressor Scripts☆30Updated 8 years ago
- External C2 Using IE COM Objects☆100Updated 6 years ago
- ☆37Updated 7 years ago