CICADA8-Research / MyMSIAnalyzerLinks
Analyse MSI files for vulnerabilities
☆139Updated last year
Alternatives and similar repositories for MyMSIAnalyzer
Users that are interested in MyMSIAnalyzer are comparing it to the libraries listed below
Sorting:
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆139Updated last year
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆203Updated 9 months ago
- Source code and examples for PassiveAggression☆64Updated last year
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆148Updated last year
- AutoRMM is a collection of scripts and instructions we are organizing, to test delivery mechanisms for RMM and screen sharing tools, alo…☆90Updated 4 months ago
- ☆108Updated last year
- Our Tips&Tricks☆127Updated 9 months ago
- Situational Awareness script to identify how and where to run implants☆67Updated last year
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Updated 8 months ago
- Permanently disable EDRs as local admin☆122Updated 2 months ago
- ☆59Updated last year
- POC of GITHUB simple C2 in rust☆52Updated 4 months ago
- Go collector for adding Ansible WorX and Ansible Tower attack paths to BloodHound with OpenGraph☆61Updated this week
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 6 years ago
- ☆147Updated 2 months ago
- Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement☆180Updated 6 months ago
- Convert your shellcode into an ASCII string☆125Updated 5 months ago
- Windows Administrator level Implant.☆50Updated last year
- ☆164Updated 9 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆50Updated last year
- Persist like a Dodder☆66Updated 6 months ago
- Execute shellcode via ASPNET compiler☆58Updated 2 months ago
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆138Updated last year
- ☆120Updated last year
- Inject RDPThief into memory with PowerShell.☆65Updated 10 months ago
- ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminatin…☆119Updated 10 months ago
- PowerShell script to generate ShellCode in various formats☆46Updated last year
- Enumerate active EDR's on the system☆146Updated 2 months ago
- POC for CVE-2024-3183 (FreeIPA Rosting)☆25Updated last year
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆86Updated last week