Sw4mpf0x / PowerLurk
Malicious WMI Events using PowerShell
☆376Updated 8 years ago
Alternatives and similar repositories for PowerLurk:
Users that are interested in PowerLurk are comparing it to the libraries listed below
- The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification☆375Updated 5 years ago
- ☆514Updated 2 years ago
- Chameleon: A tool for evading Proxy categorisation☆471Updated last month
- This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance…☆437Updated 7 years ago
- Detect and abuse risky SPNs☆260Updated 7 years ago
- ☆256Updated 2 years ago
- PSAmsi is a tool for auditing and defeating AMSI signatures.☆388Updated 6 years ago
- ☆306Updated 6 years ago
- Exchange privilege escalations to Active Directory☆743Updated last year
- Active Directory ACL exploitation with BloodHound☆708Updated 3 years ago
- getsystem via parent process using ps1 & embeded c#☆390Updated last year
- PowerShell Remote Download Cradle Generator & Obfuscator☆824Updated 6 years ago
- Enumerate all network shares in the current domain. Also, can resolve names to IP addresses.☆281Updated 4 years ago
- SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket☆790Updated 3 years ago
- DEPRECATED SharpRoast is a C# port of various PowerView's Kerberoasting functionality.☆253Updated 6 years ago
- Assorted scripts and one off things☆262Updated 4 months ago
- Analyze ARP requests to identify intercommunicating hosts and stale network address configurations (SNACs)☆63Updated 3 years ago
- Recon-AD, an AD recon tool based on ADSI and reflective DLL’s☆318Updated 5 years ago
- An LDAP based Active Directory user and group enumeration tool☆305Updated last year
- Asynchronous Password Spraying Tool in C# for Windows Environments☆308Updated last year
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆245Updated 4 years ago
- Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled.☆198Updated 6 years ago
- Search for potential frontable domains☆620Updated last year
- RACE is a PowerShell module for executing ACL attacks against Windows targets.☆216Updated last year
- SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.☆662Updated 5 years ago
- Exchange your privileges for Domain Admin privs by abusing Exchange☆993Updated 4 years ago
- NTLMv1 Multitool☆597Updated 3 months ago
- LDAP library for auditing MS AD☆392Updated 2 weeks ago
- NetSPI PowerShell Scripts☆328Updated last year