bananabr / TimeException
A tool to find folders excluded from AV real-time scanning using a time oracle
☆230Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for TimeException
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆301Updated 8 months ago
- ☆217Updated last year
- ☆294Updated 3 weeks ago
- ☆181Updated 2 years ago
- ☆377Updated last year
- A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!☆317Updated 4 months ago
- Recovering NTLM hashes from Credential Guard☆327Updated last year
- Apply a divide and conquer approach to bypass EDRs☆275Updated last year
- Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types☆372Updated last year
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆258Updated 2 years ago
- ☆295Updated last year
- A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.☆313Updated last year
- Hookers are cooler than patches.☆166Updated 2 years ago
- ☆279Updated 3 weeks ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆377Updated 7 months ago
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆250Updated last year
- Timeroasting scripts by Tom Tervoort☆182Updated last year
- Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin pr…☆216Updated last year
- RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows☆6Updated 2 years ago
- ☆178Updated this week
- A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user☆249Updated 2 years ago
- ☆267Updated last year
- ☆350Updated 3 years ago
- Identifies the bytes that Microsoft Defender flags on.☆75Updated 2 years ago
- Fully modular persistence framework☆248Updated last year
- Python tool to Check running WebClient services on multiple targets based on @leechristensen☆252Updated 3 years ago
- Generate an obfuscated DLL that will disable AMSI & ETW☆315Updated 4 months ago
- ☆143Updated last year
- Koppeling x Metatwin x LazySign☆203Updated 3 years ago
- ☆203Updated 2 years ago