dub-flow / worst-fit-poc
This repo contains a PoC of exploiting Worst Fit (props to Orange Tsai and Splitline who presented this research at Black Hat EMEA 2024)
☆10Updated last month
Alternatives and similar repositories for worst-fit-poc:
Users that are interested in worst-fit-poc are comparing it to the libraries listed below
- Lifetime AMSI bypass.☆35Updated 6 months ago
- Dump Kerberos tickets from the KCM database of SSSD☆49Updated 4 months ago
- Source code and examples for PassiveAggression.☆54Updated 7 months ago
- Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.☆31Updated last week
- StealthGuardian is a middleware layer that can be combined with adversary simulation tools to verify the resistance, detection level and…☆15Updated 5 months ago
- 🌩️ Collection of BloodHound queries for Azure☆47Updated last week
- Impacket pre-compiled binaries☆15Updated last year
- ☆48Updated 2 months ago
- Quick and dirty PowerShell script to abuse the overly permissive capabilities of the SYSTEM user in a child domain on the Public Key Serv…☆25Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 7 months ago
- Items related to the RedELK workshop given at security conferences☆27Updated last year
- Automatically extract and decrypt all configured scanning credentials of a Lansweeper instance.☆35Updated last month
- Scripts to interact with Microsoft Graph APIs☆32Updated 2 months ago
- Situational Awareness script to identify how and where to run implants☆41Updated last month
- Launches a limited shell using PowerShell Runspaces with an optional AMSI Bypass. Does not invoke Powershell.exe☆13Updated last year
- A small red team course☆34Updated last year
- ☆47Updated last year
- Sliver extension to bypass UAC via cmstp written in rust☆22Updated 7 months ago
- Discord C2 Profile for Mythic☆26Updated 9 months ago
- Create PDFs with HTML smuggling attachments that save on opening the document.☆29Updated last year
- This map lists the essential techniques to bypass anti-virus and EDR☆15Updated last year
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆29Updated last month
- ☆10Updated last month
- ☆11Updated 6 months ago
- Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL☆20Updated 2 years ago
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆39Updated 7 months ago
- Mythic C2 wrapper for NimSyscallPacker☆22Updated last month
- exfiltration/infiltration toolkit☆23Updated last year
- Docker container for running CobaltStrike 4.7 and above☆13Updated 2 years ago
- Enumerate the Domain for Readable and Writable Shares☆16Updated 7 months ago