jsecurity101 / LDAPMon
☆45Updated last year
Alternatives and similar repositories for LDAPMon:
Users that are interested in LDAPMon are comparing it to the libraries listed below
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- a tiny program to consume from ETW providers for research☆47Updated 4 months ago
- ☆75Updated 2 years ago
- ☆41Updated 9 months ago
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 9 months ago
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆52Updated 4 years ago
- ☆74Updated 9 months ago
- Python module for running BOFs☆70Updated last year
- ☆21Updated last year
- ☆14Updated last year
- Parse SDDL strings☆35Updated last year
- Python tool to find vulnerable AD object and generating csv report☆26Updated 2 years ago
- Microsoft Graph API post-exploitation toolkit☆94Updated 9 months ago
- ☆20Updated 3 years ago
- SACL Scanner is a tool designed to scan and analyze SACLs.☆38Updated 2 months ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆81Updated 2 years ago
- A technique for Active Directory domain persistence☆39Updated last year
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆56Updated 2 years ago
- Modified-Thycotic-Secret-Stealer for use with DPAPI and offline Decryption☆19Updated 2 years ago
- RDLL for Cobalt Strike beacon to silence sysmon process☆88Updated 2 years ago
- Self Delete DLL☆23Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Updated last year
- ☆58Updated 3 years ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Parser and reconciliation tooling for large Active Directory environments.☆33Updated 2 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- ☆38Updated 2 years ago