lkarlslund / nifo
Nuke It From Orbit - remove AV/EDR with physical access
โ252Updated last month
Alternatives and similar repositories for nifo:
Users that are interested in nifo are comparing it to the libraries listed below
- An ADCS honeypot to catch attackers in your internal network.โ248Updated 6 months ago
- A delicious, but malicious SSL-VPN server ๐ฎโ195Updated last month
- MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.โ236Updated 5 months ago
- โ185Updated 11 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. Tโฆโ115Updated last month
- Abusing Intune for Lateral Movement over C2โ307Updated this week
- โ296Updated 2 months ago
- โ179Updated last month
- Retired TrustedSec Capabilitiesโ243Updated last month
- โ185Updated 3 months ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local filesโ123Updated 7 months ago
- A BloodHound collector for Microsoft Configuration Managerโ275Updated 2 weeks ago
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDACโ306Updated last week
- A collection of tools, scripts and personal researchโ120Updated 6 months ago
- Simulate the behavior of AV/EDR for malware development training.โ460Updated 11 months ago
- Respotter is a Responder honeypot. Detect Responder in your environment as soon as it's spun up.โ189Updated last week
- Find potential DLL Sideloads on your windows computerโ168Updated this week
- A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.โ337Updated 9 months ago
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domaiโฆโ215Updated 3 weeks ago
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtimeโ182Updated 6 months ago
- A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you comโฆโ165Updated 2 months ago
- PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectorโฆโ271Updated last month
- Tools for interacting with authentication packages using their individual message protocolsโ303Updated 2 weeks ago
- A comprehensive tool that provides an insightful analysis of Microsoft's monthly security updates.โ176Updated 5 months ago
- Python implementation of GhostPack's Seatbelt situational awareness toolโ235Updated 2 months ago
- A curated list of awesome LOLBins, GTFO projects, and similar 'Living Off the Land' security resources.โ130Updated 2 months ago
- A repository of credential stealer formatsโ129Updated this week
- Analyse your malware to surgically obfuscate itโ434Updated last year
- Scan vulnerable drivers on Windows with loldrivers.ioโ171Updated last year
- Tools for analyzing EDR agentsโ214Updated 7 months ago