bodik / awesome-potatoes
Study notes on Windows NTLM Reflection and token stealing based EOPs.
☆17Updated 3 years ago
Alternatives and similar repositories for awesome-potatoes:
Users that are interested in awesome-potatoes are comparing it to the libraries listed below
- Perform Windows domain enumeration via LDAP☆36Updated 2 years ago
- c# reverse shell poc☆26Updated 6 years ago
- Modified version of PEAS client for offensive operations☆39Updated 2 years ago
- ☆35Updated 4 years ago
- Slides for the talk we presented as UniPi at DefCon's Red Team Village☆23Updated 2 years ago
- Log converter from CS log to Ghostwriter CSV☆29Updated 4 years ago
- ☆16Updated last year
- Convert ldapdomaindump to Bloodhound☆79Updated last year
- ☆30Updated 2 years ago
- A cloud automation system for Red Teams based on Terraform and Ansible☆24Updated 3 years ago
- Bypass Constrained Language Mode in PowerShell☆27Updated 5 years ago
- Some of my custom "tools".☆22Updated 3 years ago
- Multi-threaded C2 framework built in Flask with keylogger - from the Offensive C# Course by Naga Sai Nikhil☆21Updated 2 years ago
- ☆31Updated 4 years ago
- ☆17Updated 4 years ago
- Execute Mimikatz with different technique☆51Updated 3 years ago
- Tests for LFI in PHP apps and automates the process of leveraging LFI's to recursively download source code and discover new files via in…☆13Updated 2 years ago
- A script that parses PowerView's output for GPO analysis. Integrated into bloodhound to find misconfigurations of URA, SMB signing etc☆13Updated 5 years ago
- Tool for pivoting over SMB pipes☆17Updated 5 years ago
- A little implant which SSH's back with a shell☆36Updated 3 years ago
- Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them b…☆20Updated 11 months ago
- OSED Practice binary☆24Updated last year
- ☆19Updated 4 years ago
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆46Updated 4 years ago
- Utility to analyse, ingest and push out credentials from common data sources during an internal penetration test.☆19Updated 2 years ago
- A Couple of Python Scripts Leveraging MS365's GraphAPI to Send Custom Calendar Events / Emails from Cheap O365 Accounts☆17Updated 11 months ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆32Updated 2 years ago
- A tool to abuse Exchange services☆10Updated last year
- ☆17Updated last year
- PoC for CVE-2021-4034 dubbed pwnkit☆34Updated 3 years ago