OTRF / BHEU22-ADFS
Writing Your Own Ticket to the Cloud Like APT: A Deep-dive to AD FS Attacks, Detections, and Mitigations
☆12Updated 2 years ago
Alternatives and similar repositories for BHEU22-ADFS:
Users that are interested in BHEU22-ADFS are comparing it to the libraries listed below
- ☆33Updated 3 years ago
- The repository accompanying the Buer Emulation workshop☆24Updated 3 years ago
- A collection of my presentation materials.☆17Updated last year
- Dump Lsass Memory Using a Reflective Dll☆14Updated 3 years ago
- ☆45Updated last year
- Progress of learning kernel development☆14Updated 2 years ago
- Rapidly building a Windows 10 system to use for dynamic malware analysis (sandbox), sending data to Elastic Cloud.☆50Updated last year
- ☆18Updated last year
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆49Updated 3 years ago
- Extension functionality for the NightHawk operator client☆27Updated last year
- A C implementation of the Sektor7 "A Thief" Windows privesc technique.☆62Updated 3 years ago
- Defeating Anti-Debugging Techniques for Malware Analysis☆13Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- ☆17Updated 9 months ago
- Continuous kerberoast monitor☆45Updated last year
- ☆12Updated 2 years ago
- Tricard - Malware Sandbox Fingerprinting☆20Updated last year
- Playing with PE's and Building Structures by Hand☆22Updated 3 years ago
- Get-PDInvokeImports is tool (PowerShell module) which is able to perform automatic detection of P/Invoke, Dynamic P/Invoke and D/Invoke u…☆54Updated 3 years ago
- ☆14Updated last month
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆21Updated last year
- ☆48Updated 3 years ago
- Quickly search for references to a GUID in DLLs, EXEs, and drivers☆74Updated 3 years ago
- Finds imports that could be exploited, still requires manual analysis.☆27Updated 2 years ago
- Collection of generic YARA rules☆16Updated 10 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆26Updated 2 months ago
- ProcDot Malware Sandbox☆24Updated 5 months ago
- ☆24Updated 3 years ago
- ☆22Updated 11 months ago