MHaggis / NEBULALinks
Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques
☆72Updated 3 weeks ago
Alternatives and similar repositories for NEBULA
Users that are interested in NEBULA are comparing it to the libraries listed below
Sorting:
- AutoRMM is a collection of scripts and instructions we are organizing, to test delivery mechanisms for RMM and screen sharing tools, alo…☆91Updated 5 months ago
- BeaconatorC2 is a framework for red teaming and adversarial emulation, providing a full-featured management interface, along with a catal…☆92Updated this week
- Persist like a Dodder☆67Updated 8 months ago
- Baseline a Windows System against LOLBAS☆70Updated last year
- Microsoft Graph API post-exploitation toolkit☆95Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆92Updated last year
- BloodHound PowerShell client☆75Updated last month
- Living off the land searches for explorer and sharepoint☆92Updated last month
- Ludus range for the Constructing Defense Lab☆71Updated 2 months ago
- Step-by-step documentation on how to decrypt SCCM database secrets offline☆50Updated 3 months ago
- Living Off the Foreign Land setup scripts☆74Updated 10 months ago
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆43Updated 11 months ago
- Source code and examples for PassiveAggression☆64Updated last year
- ☆34Updated 5 months ago
- An Ansible collection that installs an ADFS deployment with optional configurations.☆43Updated last month
- An offensive toolkit for restless guests #DEFCON33☆54Updated 5 months ago
- POC tool to abuse windows server failover clusters☆53Updated 5 months ago
- This script analyzes the DCSync output file from several tools (such as Mimikatz, Secretsdump and SharpKatz...)☆66Updated 10 months ago
- ☆134Updated 4 months ago
- ☆24Updated 11 months ago
- BypassIT is a framework for covert malware delivery and post-exploitation using AutoIT for red / blue team self assessment.☆46Updated 6 months ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆96Updated 2 years ago
- Block Windows Defender by deny ACL☆72Updated last week
- Lifetime AMSI bypass.☆36Updated 8 months ago
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆35Updated last year
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated last year
- Tool to extract username and password of current user from PanGPA in plaintext☆88Updated last year
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆256Updated 3 months ago
- ☆43Updated last year
- ☆47Updated last year