connormcgarr / tgtdelegation
tgtdelegation is a Beacon Object File (BOF) to obtain a usable TGT via the "TGT delegation trick"
☆173Updated 3 years ago
Alternatives and similar repositories for tgtdelegation:
Users that are interested in tgtdelegation are comparing it to the libraries listed below
- InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assem…☆190Updated 3 years ago
- ☆141Updated 2 years ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆133Updated last year
- COFF file (BOF) for managing Kerberos tickets.☆294Updated last year
- Beacon Object File & C# project to check LDAP signing☆189Updated 8 months ago
- Hookers are cooler than patches.☆170Updated 3 years ago
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆122Updated 3 years ago
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆254Updated last year
- Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations☆153Updated last year
- Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from mem…☆113Updated last year
- Patch AMSI and ETW☆236Updated 11 months ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆175Updated 2 years ago
- ☆151Updated 2 months ago
- ☆114Updated last year
- ADCS cert template modification and ACL enumeration☆136Updated last year
- ☆88Updated 2 years ago
- Coerce Windows machines auth via MS-EVEN☆159Updated last year
- OPSEC safe Kerberoasting in C#☆191Updated 2 years ago
- ☆159Updated 5 months ago
- A tool for converting SysWhispers2 syscalls for use with Nim projects☆119Updated 3 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆142Updated 11 months ago
- Source generator to add D/Invoke and indirect syscall methods to a C# project.☆177Updated last year
- A fake AMSI Provider which can be used for persistence.☆150Updated 3 years ago
- C# version of Powermad☆165Updated last year
- Koppeling x Metatwin x LazySign☆210Updated 3 years ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆91Updated 2 years ago
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆90Updated 11 months ago
- ☆83Updated last year
- Simple BOF to read the protection level of a process☆115Updated last year
- Find .net assemblies locally☆111Updated 2 years ago