GhostPack / Invoke-Evasion
PowerShell Obfuscation and Data Science
☆172Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for Invoke-Evasion
- Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.☆117Updated 2 years ago
- Koppeling x Metatwin x LazySign☆203Updated 3 years ago
- OPSEC safe Kerberoasting in C#☆188Updated 2 years ago
- ☆202Updated 2 years ago
- ☆152Updated this week
- ☆118Updated last year
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆119Updated 3 years ago
- pyCobaltHound is an Aggressor script extension for Cobalt Strike which aims to provide a deep integration between Cobalt Strike and Blood…☆134Updated last year
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆166Updated last year
- ☆160Updated 2 years ago
- Some scripts to support with importing large datasets into BloodHound☆76Updated 11 months ago
- ☆143Updated last year
- Modular C# framework to exfiltrate loot over secure and trusted channels.☆120Updated 3 years ago
- ☆175Updated this week
- The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.☆108Updated 4 years ago
- Bypassing AppLocker with C#☆136Updated 3 years ago
- Weaponising C# - Fundamentals Training Content☆71Updated 3 years ago
- SpecterOps Presentations☆178Updated 3 months ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆134Updated 5 months ago
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆250Updated last year
- Slide decks and/or materials from conference presentations☆54Updated last year
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆258Updated 2 years ago
- ☆112Updated last year
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆79Updated 6 months ago
- ☆133Updated last year
- Identifies the bytes that Microsoft Defender flags on.☆75Updated 2 years ago
- Hookers are cooler than patches.☆166Updated 2 years ago
- ☆241Updated last year
- Collection of tools to use with Azure Applications☆107Updated last year