RomanEmelyanov / CobaltStrikeForensicLinks
Toolset for research malware and Cobalt Strike beacons
☆211Updated 4 months ago
Alternatives and similar repositories for CobaltStrikeForensic
Users that are interested in CobaltStrikeForensic are comparing it to the libraries listed below
Sorting:
- Static based decoders for malware samples☆93Updated 4 years ago
- Splunk Dashboard for CobaltStrike logs☆89Updated 4 years ago
- Ex-pv8's☆64Updated 5 years ago
- Simulating Adversary Operations☆93Updated 7 years ago
- Historical list of {Cobalt Strike,NanoHTTPD} servers☆121Updated 6 years ago
- DLL Password Filter Implant with Exfiltration Capabilities☆138Updated 5 years ago
- A collection of scripts for dealing with Cobalt Strike beacons in Python☆168Updated 4 years ago
- Automated Tactics Techniques & Procedures☆255Updated 2 years ago
- ☆81Updated 8 years ago
- ☆82Updated 4 years ago
- Aggregation of Cobalt Strike's aggressor scripts.☆143Updated 7 years ago
- Windows RID Hijacking persistence technique☆175Updated 7 months ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆72Updated 3 years ago
- A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.☆169Updated 4 months ago
- Constrained Language Mode + AMSI bypass all in one☆157Updated 5 years ago
- Powershell script for enumerating vulnerable DCOM Applications☆260Updated 6 years ago
- Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.☆140Updated 7 years ago
- CobaltStrike External C2 for Websockets☆193Updated 6 years ago
- Detect possible sysmon logging bypasses given a specific configuration☆111Updated 6 years ago
- a tool to make it easy and fast to test various forms of injection☆172Updated 6 years ago
- Repo containing docker-compose files and setup scripts without having to clone the individual reternal components☆109Updated 4 years ago
- PowerShell script for hunting webshells on Microsoft Exchange Servers.☆56Updated 8 years ago
- lateral movement techniques that can be used during red team exercises☆273Updated 5 years ago
- PowerAvails is a unit of collection of Powershell modules that help you get done many things☆119Updated 6 years ago
- An Insider Threat Toolkit☆152Updated 6 years ago
- Cuckoo running in a nested hypervisor☆128Updated 5 years ago
- Some .ps1 scripts for pentesting☆132Updated 4 years ago
- Community maintained list of most popular HIPS service and process names on a Windows Platform.☆43Updated 3 years ago
- Petaq - Purple Team Command & Control Server☆105Updated 2 years ago
- ☆58Updated 4 years ago