lkarlslund / nifo
Nuke It From Orbit - remove AV/EDR with physical access
☆253Updated 2 months ago
Alternatives and similar repositories for nifo:
Users that are interested in nifo are comparing it to the libraries listed below
- ☆185Updated last year
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆334Updated last month
- MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.☆250Updated 6 months ago
- An ADCS honeypot to catch attackers in your internal network.☆280Updated 7 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆118Updated 3 weeks ago
- A BloodHound collector for Microsoft Configuration Manager☆301Updated last month
- Abusing Intune for Lateral Movement over C2☆325Updated last week
- ☆191Updated last week
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆250Updated 3 weeks ago
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆225Updated last month
- ☆188Updated 4 months ago
- Respotter is a Responder honeypot. Detect Responder in your environment as soon as it's spun up.☆191Updated last month
- A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.☆361Updated 3 weeks ago
- Tools for interacting with authentication packages using their individual message protocols☆306Updated 3 weeks ago
- A delicious, but malicious SSL-VPN server 🌮☆205Updated 2 months ago
- ☆296Updated 3 months ago
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆177Updated 10 months ago
- Simulate the behavior of AV/EDR for malware development training.☆461Updated last year
- Retired TrustedSec Capabilities☆245Updated 2 months ago
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆163Updated 4 months ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆123Updated 8 months ago
- The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory C…☆249Updated last year
- A security assessment tool for analyzing Active Directory Group Policy Objects (GPOs) to identify misconfigurations and vulnerabilities☆193Updated last month
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆186Updated 7 months ago
- Find potential DLL Sideloads on your windows computer☆175Updated last month
- Tools for analyzing EDR agents☆220Updated 8 months ago
- Python implementation of GhostPack's Seatbelt situational awareness tool☆241Updated 3 months ago
- A curated list of awesome LOLBins, GTFO projects, and similar 'Living Off the Land' security resources.☆140Updated 3 months ago
- Python tool to check rootkits in Windows kernel☆192Updated 2 weeks ago
- A collection of tools, scripts and personal research☆125Updated 7 months ago