lkarlslund / nifo
Nuke It From Orbit - remove AV/EDR with physical access
☆257Updated 3 months ago
Alternatives and similar repositories for nifo:
Users that are interested in nifo are comparing it to the libraries listed below
- MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.☆270Updated 7 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆121Updated 2 months ago
- A delicious, but malicious SSL-VPN server 🌮☆215Updated 3 months ago
- An ADCS honeypot to catch attackers in your internal network.☆284Updated 8 months ago
- ☆186Updated last year
- Abusing Intune for Lateral Movement over C2☆327Updated last month
- ☆203Updated this week
- A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.☆368Updated last month
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆343Updated 2 months ago
- Tools for interacting with authentication packages using their individual message protocols☆309Updated 3 weeks ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆260Updated 2 months ago
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆229Updated 2 months ago
- A BloodHound collector for Microsoft Configuration Manager☆309Updated 2 months ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆123Updated 9 months ago
- Python implementation of GhostPack's Seatbelt situational awareness tool☆255Updated 4 months ago
- The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory C…☆250Updated last year
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.☆181Updated last week
- PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirector…☆332Updated 3 months ago
- Python tool to check rootkits in Windows kernel☆195Updated 3 weeks ago
- lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection☆183Updated 2 weeks ago
- Tools for analyzing EDR agents☆221Updated 9 months ago
- A collection of tools, scripts and personal research☆127Updated 8 months ago
- Scan vulnerable drivers on Windows with loldrivers.io☆171Updated last year
- Retired TrustedSec Capabilities☆246Updated 4 months ago
- ☆190Updated 6 months ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆185Updated 9 months ago
- Respotter is a Responder honeypot. Detect Responder in your environment as soon as it's spun up.☆192Updated 2 months ago
- Find potential DLL Sideloads on your windows computer☆176Updated 2 months ago
- ☆297Updated 4 months ago
- A repository of credential stealer formats☆202Updated this week