NVISOsecurity / blogposts
A repo to house files for our blogposts on blog.nviso.eu
☆68Updated 4 months ago
Alternatives and similar repositories for blogposts:
Users that are interested in blogposts are comparing it to the libraries listed below
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- (PoC) Tiny Excel BIFF8 Generator, to Embedded 4.0 Macros in xls files without Excel.☆42Updated 3 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆53Updated 2 years ago
- PoC-Malware-TTPs☆49Updated last year
- A BOF port of the research of @thefLinkk and @codewhitesec☆95Updated 3 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆66Updated 6 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆87Updated 2 years ago
- Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions☆51Updated 3 years ago
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.☆61Updated 2 years ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆46Updated 2 years ago
- A cloud automation system for Red Teams based on Terraform and Ansible☆24Updated 3 years ago
- ☆38Updated 2 years ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Perform Windows domain enumeration via LDAP☆36Updated 2 years ago
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆30Updated 10 months ago
- ☆56Updated 3 years ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- A technique for Active Directory domain persistence☆39Updated last year
- Slide decks and/or materials from conference presentations☆55Updated 2 years ago
- A little implant which SSH's back with a shell☆36Updated 2 years ago
- WhoAmI by asking the LDAP service on a domain controller.☆59Updated 2 years ago
- Windows Persistence Toolkit in C#☆36Updated 2 years ago
- ☆45Updated last year
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆46Updated 3 years ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- ☆52Updated 3 years ago
- ☆54Updated 3 years ago
- Smart Card PIN swiping DLL☆77Updated 4 years ago