intelliroot-tech / ProcessHuntingToolkit
Process hunting Toolkit is toolkit capable of hunting down malicious processes on Windows
☆11Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for ProcessHuntingToolkit
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆72Updated 2 months ago
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆51Updated 6 months ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆53Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 4 months ago
- MITRE TTPs derived from Conti's leaked playbooks from XSS.IS☆35Updated 3 years ago
- ☆44Updated last year
- Yara Rules for Modern Malware☆67Updated 8 months ago
- Default Detections for EDR☆94Updated 9 months ago
- Create a cool process tree like https://twitter.com/ACEResponder.☆34Updated last year
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- ☆13Updated 6 months ago
- ☆67Updated 3 months ago
- A collection of Tools and Rules for decoding Brute Ratel C4 badgers☆62Updated 2 years ago
- This is a simulation of attack by Fancy Bear group (APT28) targeting high-ranking government officials Western Asia and Eastern Europe☆30Updated 5 months ago
- ☆68Updated 2 years ago
- ☆76Updated 6 months ago
- Python tool to find vulnerable AD object and generating csv report☆26Updated 2 years ago
- Utilities for obfuscating shellcode☆45Updated 4 months ago
- ☆43Updated 4 months ago
- ☆44Updated 3 weeks ago
- Repo containing my public talks☆22Updated last year
- ☆43Updated 4 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- Slide decks and/or materials from conference presentations☆54Updated 2 years ago
- Python module for running BOFs☆64Updated last year
- Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk , plus functions and strings obfuscation☆30Updated 2 years ago
- ☆80Updated 2 years ago