NotMedic / Invoke-Nanodump
HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection
☆53Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for Invoke-Nanodump
- Secretsdump C# version only supporting local (live) operation☆47Updated last year
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆65Updated last year
- ☆59Updated 3 months ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆86Updated 2 years ago
- Click Once + App Domain☆62Updated 11 months ago
- ☆61Updated 2 years ago
- Get Fine Grained Password Policy☆65Updated 6 months ago
- .NET project for installing Persistence☆64Updated 2 years ago
- Scripts for public use that we've randomly written, or have updated from other people's work.☆38Updated 4 months ago
- ☆35Updated 2 years ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged p…☆49Updated 2 years ago
- ☆68Updated last year
- A care package of useful bofs for red team engagments☆48Updated 2 years ago
- ☆138Updated 2 years ago
- ☆73Updated 7 months ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- WhoAmI by asking the LDAP service on a domain controller.☆58Updated 2 years ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆30Updated 2 years ago
- A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket☆52Updated 4 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆130Updated 2 months ago
- Simple .NET loader for loading and executing Powershell payloads☆14Updated 3 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- Cobalt Strike BOF for quser.exe implementation using Windows API☆83Updated last year
- Leveraging AWS Lambda Function URLs for C2 Redirection☆22Updated last year
- ☆36Updated last month
- Slide decks and/or materials from conference presentations☆54Updated 2 years ago
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- ☆53Updated 7 months ago
- ☆89Updated 2 years ago
- Bypass AMSI via PowerShell by splitting a file into multiple chunks☆49Updated 3 years ago