jsecurity101 / LDAPMon
☆44Updated last year
Related projects ⓘ
Alternatives and complementary repositories for LDAPMon
- Small tool to play with IOCs caused by Imageload events☆37Updated last year
- A post-exploitation strategy for persistence and egress from networks utilizing authenticated web proxies☆32Updated 2 years ago
- Parse SDDL strings☆35Updated 7 months ago
- ☆68Updated 2 years ago
- Self Delete DLL☆23Updated 9 months ago
- ☆35Updated 2 years ago
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆51Updated 4 years ago
- ☆20Updated last year
- ☆35Updated 5 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 4 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆38Updated last year
- a short C code POC to gain persistence and evade sysmon event code registry (creation, update and deletion) REG_NOTIFY_CLASS Registry Cal…☆51Updated last year
- ☆67Updated 3 months ago
- Modified-Thycotic-Secret-Stealer for use with DPAPI and offline Decryption☆18Updated 2 years ago
- ☆28Updated 5 months ago
- Python module for running BOFs☆64Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- Depending on the AV/EPP/EDR creating a Taskschedule Job with a default cradle is often flagged☆86Updated 2 years ago
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- A technique for Active Directory domain persistence☆39Updated last year
- ☆51Updated 3 years ago
- A care package of useful bofs for red team engagments☆48Updated 2 years ago
- A BOF to interact with COM objects associated with the Windows software firewall.☆100Updated 3 years ago
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 6 months ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆30Updated 2 years ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- Bunch of BOF files☆24Updated 9 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago