jconwell / secret_handshake
A prototype malware C2 channel using x509 certificates over mTLS
☆153Updated last year
Alternatives and similar repositories for secret_handshake:
Users that are interested in secret_handshake are comparing it to the libraries listed below
- Cortex XDR Config Extractor☆131Updated 2 years ago
- ☆190Updated 6 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆77Updated 7 months ago
- ☆220Updated last year
- ☆297Updated 5 months ago
- ☆115Updated 3 years ago
- A tool to find folders excluded from AV real-time scanning using a time oracle☆233Updated last year
- A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).☆93Updated 2 years ago
- ☆121Updated last year
- Some scripts to support with importing large datasets into BloodHound☆79Updated last year
- A suite of tools to disrupt campaigns using the Sliver C2 framework.☆270Updated last year
- ☆195Updated last month
- ☆139Updated 7 months ago
- Living Off the Foreign Land setup scripts☆67Updated last month
- Artificially inflate a given binary to exceed common EDR file size limits. Can be used to bypass common EDR.☆119Updated 2 years ago
- Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares☆173Updated 2 years ago
- ☆117Updated last year
- The most average C2 ever (MACE)☆96Updated 2 years ago
- A Mythic Agent written in PIC C.☆185Updated last month
- ☆186Updated last year
- POC for frustrating/defeating Malware Analysts☆154Updated 2 years ago
- C2 Automation using Linode☆80Updated 2 years ago
- Your syscall factory☆121Updated 3 weeks ago
- ☆146Updated 2 months ago
- ☆136Updated 9 months ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆141Updated 10 months ago
- An interactive shell to spoof some LOLBins command line☆184Updated last year
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆253Updated last year
- This are different types of download cradles which should be an inspiration to play and create new download cradles to bypass AV/EPP/EDR …☆257Updated 2 years ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆185Updated this week