Wh04m1001 / SysmonEoP
☆181Updated last year
Related projects ⓘ
Alternatives and complementary repositories for SysmonEoP
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆250Updated last year
- ☆159Updated last year
- Reuse open handles to dynamically dump LSASS.☆234Updated 7 months ago
- A basic emulation of an "RPC Backdoor"☆207Updated 2 years ago
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆292Updated 2 years ago
- ☆154Updated 3 months ago
- Coerce Windows machines auth via MS-EVEN☆153Updated 9 months ago
- Patch AMSI and ETW☆230Updated 6 months ago
- A BOF to automate common persistence tasks for red teamers☆267Updated last year
- You shall pass☆248Updated 2 years ago
- ☆207Updated 6 months ago
- Weaponized HellsGate/SigFlip☆191Updated last year
- POC tools for exploring SMB over QUIC protocol☆121Updated 2 years ago
- DLL Hijack Search Order Enumeration BOF☆141Updated 3 years ago
- ☆173Updated 11 months ago
- A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.☆313Updated last year
- To audit the security of read-only domain controllers☆113Updated 11 months ago
- Lateral Movement Using DCOM and DLL Hijacking☆279Updated last year
- ☆181Updated 7 months ago
- My implementation of the GIUDA project in C++☆155Updated last year
- COM Hijacking VOODOO☆257Updated 7 months ago
- COFF file (BOF) for managing Kerberos tickets.☆280Updated last year
- Useful Cobalt Strike Beacon Object Files (BOFs) used during red teaming and penetration testing engagements.☆75Updated 2 years ago
- A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY☆77Updated 2 years ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆121Updated 8 months ago
- A tool for converting SysWhispers3 syscalls for use with Nim projects☆138Updated 2 years ago
- Run Your Payload Without Running Your Payload☆176Updated 2 years ago
- The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section☆94Updated last year
- Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS☆173Updated 2 years ago