NVISOsecurity / blogpostsLinks
A repo to house files for our blogposts on blog.nviso.eu
☆71Updated 3 months ago
Alternatives and similar repositories for blogposts
Users that are interested in blogposts are comparing it to the libraries listed below
Sorting:
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- subTee gists code backups☆36Updated 7 years ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆49Updated 3 years ago
- Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions☆54Updated 3 years ago
- A PoC~ish of https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/☆31Updated last year
- A technique for Active Directory domain persistence☆39Updated 2 years ago
- (PoC) Tiny Excel BIFF8 Generator, to Embedded 4.0 Macros in xls files without Excel.☆43Updated 3 years ago
- A little implant which SSH's back with a shell☆38Updated 3 years ago
- Perform Windows domain enumeration via LDAP☆36Updated 3 years ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆90Updated 2 years ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- Tool to manage user privileges☆29Updated 5 years ago
- .NET project for installing Persistence☆64Updated 3 years ago
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.☆62Updated 3 years ago
- My BloodHound custom queries☆23Updated 2 years ago
- ☆57Updated 4 years ago
- This is a CS project that will encrypt shell code from msfvenom using AES☆22Updated 3 years ago
- all credits go to @mgeeky☆64Updated 3 years ago
- Simple HTTP async comms using standard GET/POST requests☆36Updated 3 months ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- ☆13Updated 5 years ago
- A proof-of-concept created for academic/learning purposes, demonstrating both local and remote use of VSTO "Add-In's" maliciously☆31Updated 2 years ago
- This repo hosts a poc of how to execute F# code within an unmanaged process☆67Updated last year
- PoC-Malware-TTPs☆49Updated 2 years ago
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies☆32Updated 2 years ago
- Code samples of .NET shellcode injections, weaponized for use via WebDav and mshta.exe.☆37Updated 5 years ago
- Get or remove RunMRU values☆55Updated 5 years ago
- Small POC for process ghosting☆39Updated 3 years ago
- RDPThief donut shellcode inject into mstsc☆87Updated 4 years ago
- Windows Persistence Toolkit in C#☆36Updated 2 years ago