ZephrFish / edr-checker
Gets the name of all currently running process then checks them against a list of known defensive products such as AV's, EDR's and logging tools.
☆14Updated 2 years ago
Alternatives and similar repositories for edr-checker:
Users that are interested in edr-checker are comparing it to the libraries listed below
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆83Updated 9 months ago
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆52Updated 8 months ago
- Some scripts to support with importing large datasets into BloodHound☆79Updated last year
- ☆70Updated last year
- Small utility to chunk up a large BloodHound JSON file into smaller files for importing.☆91Updated last year
- Get Fine Grained Password Policy☆67Updated 9 months ago
- A python port of @dafthack's MFAsweep with some added OPSEC functionality. MFAde can be used to find single-factor authentication failure…☆37Updated 2 years ago
- pysnaffler☆88Updated last month
- Living Off the Foreign Land setup scripts☆64Updated last month
- Small project to facilitate creation of .lnk payloads☆63Updated 2 years ago
- ☆85Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆41Updated 4 months ago
- A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket☆54Updated 4 years ago
- Red Team "Drop and Run" NAC (802.1x) Bypass☆70Updated last year
- A Python POC for CRED1 over SOCKS5☆139Updated 4 months ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆126Updated 11 months ago
- ☆36Updated 3 years ago
- ☆157Updated 3 months ago
- OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.☆90Updated 2 years ago
- ☆40Updated 3 weeks ago
- ☆99Updated 10 months ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- ☆35Updated last year
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Leveraging AWS Lambda Function URLs for C2 Redirection☆26Updated last year
- Collection of tools to use with Azure Applications☆107Updated last year
- ☆144Updated last week
- ☆64Updated 11 months ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆73Updated 2 years ago
- Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.☆119Updated 2 years ago