CrowdStrike / OWASSRF
☆13Updated 2 years ago
Alternatives and similar repositories for OWASSRF:
Users that are interested in OWASSRF are comparing it to the libraries listed below
- Detect WFP filters blocking EDR communications☆86Updated last year
- PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory …☆93Updated last year
- Active C&C Detector☆153Updated last year
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Protect your Domain Controllers by auditing and restricting LDAP requests☆151Updated 3 months ago
- Abuse Azure API permissions for red teaming☆66Updated 2 years ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 7 months ago
- Default Detections for EDR☆96Updated last year
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆139Updated 8 months ago
- ☆190Updated 7 months ago
- Lateral Movement☆122Updated last year
- ☆82Updated 2 years ago
- ☆200Updated last year
- Microsoft Graph API post-exploitation toolkit☆94Updated 9 months ago
- This repo will contain the core detection, only for Cobaltstrike's leaked versions. Non-leaked version detections wont be shared☆89Updated last year
- Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-nat…☆161Updated last week
- ☆178Updated 4 months ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆205Updated 2 weeks ago
- Tool for viewing NTDS.dit☆155Updated last month
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆171Updated 2 years ago
- ☆148Updated 2 months ago
- Living off the land searches for explorer and sharepoint☆78Updated 5 months ago
- ☆139Updated 8 months ago
- Automated exploitation of MSSQL servers at scale☆108Updated 2 weeks ago
- ☆160Updated last year
- ☆88Updated last week
- ☆151Updated 2 months ago
- Resources Links for the Research Based on Josh Prager and Nico Shyne's☆13Updated 6 months ago
- A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.☆150Updated 11 months ago
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆122Updated 3 years ago