Hubbl3 / ThreatCheck
Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.
☆12Updated 9 months ago
Alternatives and similar repositories for ThreatCheck:
Users that are interested in ThreatCheck are comparing it to the libraries listed below
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 8 months ago
- Scripts to interact with Microsoft Graph APIs☆33Updated 3 months ago
- Quick and dirty PowerShell script to abuse the overly permissive capabilities of the SYSTEM user in a child domain on the Public Key Serv…☆25Updated last year
- Create PDFs with HTML smuggling attachments that save on opening the document.☆29Updated last year
- Mythic C2 wrapper for NimSyscallPacker☆21Updated 2 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 9 months ago
- Python3 rewrite of AsOutsider features of AADInternals☆40Updated 2 months ago
- Items related to the RedELK workshop given at security conferences☆28Updated last year
- Excel Add In Payload Generator☆10Updated last year
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 9 months ago
- Situational Awareness script to identify how and where to run implants☆45Updated 2 months ago
- ☆17Updated 2 months ago
- Enumerate the Domain for Readable and Writable Shares☆16Updated this week
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- A vSphere deployment of GOADv2 BETA Testing (v0.1)☆26Updated last year
- ☆25Updated last year
- Nemesis agent for Mythic☆26Updated 5 months ago
- Launches a limited shell using PowerShell Runspaces with an optional AMSI Bypass. Does not invoke Powershell.exe☆13Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 7 months ago
- ☆47Updated 2 years ago
- A C# program featuring an all-in-one bypass for CLM, AppLocker and AMSI using Runspace.☆18Updated 2 years ago
- A script that parses PowerView's output for GPO analysis. Integrated into bloodhound to find misconfigurations of URA, SMB signing etc☆13Updated 5 years ago
- ☆15Updated last year
- A lightweight HTTP/HTTPS reverse proxy for efficient, policy-based traffic filtering and redirection.☆42Updated last year