BorjaMerino / DoublePulsar-Volatility
Volatility plugin to help identify DoublePulsar implant by listing the array of pointers SrvTransaction2DispatchTable from the srv.sys driver.
☆16Updated 7 years ago
Alternatives and similar repositories for DoublePulsar-Volatility:
Users that are interested in DoublePulsar-Volatility are comparing it to the libraries listed below
- Material from our CANAPE workshop☆32Updated 6 years ago
- An offensive Powershell console☆30Updated 9 years ago
- Comprehensive Pivoting Framework☆20Updated 8 years ago
- ☆17Updated 7 years ago
- Various snippets created during malware analysis☆22Updated 6 years ago
- Beagle(bone) in the Middle☆25Updated 4 years ago
- WhiteBox CMS analysis☆69Updated last year
- ☆25Updated 8 years ago
- A C# web handler that is vulnerable to XXE with PoC. This is to serve as an example of what vulnerable C# code looks like.☆26Updated 11 years ago
- Development guide for Volatility Plugins☆23Updated 7 years ago
- put this here because archival reasons.☆28Updated 7 years ago
- Talk given at DerbyCon and RuxCon 2016☆22Updated 8 years ago
- Parses Java Cache IDX files☆39Updated 6 years ago
- Simple DDE object detector☆56Updated 7 years ago
- PowerShell Empire docker build☆23Updated 8 years ago
- A simplified SMB Email Client Attack script used for pentests.☆30Updated 6 years ago
- This script is used for extracting DDE in docx and xlsx☆12Updated 7 years ago
- Tool orchestrator. Specify targets and run sets of tools against them.☆19Updated 8 years ago
- Office 365 MFA capture toolkit☆12Updated 7 years ago
- Issues to consider when planning a red team exercise.☆14Updated 7 years ago
- This tool will extract useful information from the McAfee update SiteList file and decrypt the associated password for each entry.☆26Updated 7 years ago
- McAfee ePolicy 0wner exploit code☆46Updated 6 years ago
- Materials related to the 2017 BSides Las Vegas presentation☆51Updated 4 years ago
- Ransack Post Exploitation Tool☆16Updated 8 years ago
- Historical Observations of Actionable Reputation Data☆13Updated 6 years ago
- A ready to deploy docker container for a fresh sandbox for on-the-fly malware analysis☆43Updated 7 years ago
- Squirtle the Browser-based NTLM Attack Toolkit☆18Updated 9 years ago
- Environmental (and http) keying for scripting languages☆39Updated 6 years ago
- Shows command lines used by latest instances analyzed on Hybrid-Analysis☆43Updated 6 years ago
- Mimikatz HashClash☆12Updated 9 years ago