danzek / awesome-lol-commonly-abusedLinks
Awesome list of Living off the Land (LOL) methods, tools, and features commonly abused by attackers
☆31Updated 7 months ago
Alternatives and similar repositories for awesome-lol-commonly-abused
Users that are interested in awesome-lol-commonly-abused are comparing it to the libraries listed below
Sorting:
- EventLogSilencer is a PowerShell script designed for disable Windows Event Logging☆17Updated 2 years ago
- Detonate malware on VMs and get logs & detection status☆60Updated last week
- Extension functionality for the NightHawk operator client☆26Updated 2 years ago
- CyberWarFare Labs hands-on workshop on the topic "Detecting Adversarial Tradecrafts/Tools by leveraging ETW"☆51Updated 3 years ago
- Slides from my talk at the Adversary Village, Defcon 30☆29Updated 2 years ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Updated 3 years ago
- CIS Benchmark testing of Windows SIEM configuration☆45Updated 2 years ago
- ☆55Updated 10 months ago
- ☆45Updated 2 years ago
- ☆19Updated 2 years ago
- Automatically spider the result set of a Censys/Shodan search and download all files where the file name or folder path matches a regex.☆28Updated 2 years ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆53Updated 2 years ago
- WMI SA stuffs☆30Updated 3 years ago
- MSIX Building Made Easy for Defenders☆58Updated 2 months ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆41Updated 4 years ago
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Updated 2 years ago
- A user enumeration tool for Slack.☆31Updated last year
- Detection Engineering Tools☆17Updated 2 weeks ago
- ☆11Updated last year
- Scans a list of raccoon servers from Tria.ge and extracts the config☆15Updated 2 years ago
- AutoPoC Generator HoneyPoC☆35Updated 6 months ago
- Timestomp Tool to flatten MAC times with a specific timestamp☆48Updated 6 months ago
- Code for profiling sandboxes - Initially an idea to profile sandboxes, the code is written to take enviromental variables and send them b…☆21Updated 2 months ago
- A cap/pcap packet parser to make life easier when performing stealth/passive reconnaissance.☆22Updated last year
- Tool for obtaining information about PPL processes☆16Updated last year
- A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro…☆25Updated 3 years ago
- Items related to the RedELK workshop given at security conferences☆29Updated 2 years ago
- This script generates a groups.xml file that mimics a real GPP to create a new user on domain-joined computers☆46Updated 5 years ago
- A project created with an aim to emulate and test exfiltration of data over different network protocols.☆31Updated 2 years ago
- Placeholder for my detection repo and misc detection engineering content☆42Updated 2 years ago