SafeBreach-Labs / spacebin
Spacebin is a proof-of-concept malware that exfiltrates data (from No Direct Internet Access environments) via triggering AV on the endpoint and then communicating back from the AV's cloud component.
☆85Updated 7 years ago
Alternatives and similar repositories for spacebin:
Users that are interested in spacebin are comparing it to the libraries listed below
- Data Exfiltration and Command Execution via AAAA Records☆67Updated 8 years ago
- Proof-of-concept two-stage dropper generator that uses bits from external sources☆98Updated 7 years ago
- ☆59Updated 5 years ago
- Credential Phish Analysis and Automation☆96Updated 6 years ago
- BTG's purpose is to make fast and efficient search on IOC☆70Updated 6 years ago
- ☆97Updated 9 years ago
- ☆46Updated 7 years ago
- IR-Tools - PowerShell tools for IR☆130Updated 7 years ago
- Computer Network Defender's Toolkit, specializing in active defense techniques.☆7Updated 5 years ago
- ☆108Updated 8 years ago
- Various public documents, whitepapers and articles about APT campaigns☆54Updated 8 years ago
- A python script used to parse the SAM registry hive.☆72Updated 7 years ago
- PowerShell scripts for Hard Drive forensics and parsing Windows Artifacts☆56Updated 4 years ago
- Query Active Directory for Workstations and then pull their Wireless Network Passwords☆46Updated 7 years ago
- A powershell script for creating a Windows honeyport.☆87Updated 9 years ago
- An automated collection and analysis of malware from my honeypots.☆25Updated 7 years ago
- ☆73Updated 2 years ago
- Command line tool for scanning streams within office documents plus xor db attack☆126Updated last year
- A python implementation of a grep friendly ftrace wrapper☆80Updated 5 years ago
- Recurse through a registry, identifying values with large data -- a registry malware hunter☆44Updated 8 years ago
- ☆68Updated 7 years ago
- A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service), allowing arbitrary program execution as th…☆98Updated 5 years ago
- A collection of scripts to initialize a windows VM to run all the malwares!☆106Updated 4 years ago
- ☆112Updated 7 years ago
- ☆114Updated 7 years ago
- Mystique may be used to discover infection markers that can be used to vaccinate endpoints against malware. It receives as input a malici…☆82Updated 7 years ago
- An extensible honeypot framework☆93Updated 2 years ago
- Sandbox feature upgrade with the help of wrapped samples☆76Updated 6 years ago
- Clustering NMAP XML results to help make sense of large scan results.☆33Updated 2 years ago
- Various config files obtained during malware analysis☆67Updated 6 years ago