lkarlslund / nifo
Nuke It From Orbit - remove AV/EDR with physical access
☆181Updated last week
Related projects ⓘ
Alternatives and complementary repositories for nifo
- MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.☆218Updated 3 months ago
- ☆181Updated 9 months ago
- ☆180Updated last month
- Tools for analyzing EDR agents☆208Updated 5 months ago
- ☆130Updated last month
- A CIA tradecraft technique to asynchronously detect when a process is created using WMI.☆131Updated 10 months ago
- An ADCS honeypot to catch attackers in your internal network.☆222Updated 4 months ago
- ☆293Updated 2 weeks ago
- Abusing Intune for Lateral Movement over C2☆269Updated last week
- Tools for interacting with authentication packages using their individual message protocols☆296Updated last week
- Hide shellcode by shuffling bytes into a random array and reconstruct at runtime☆178Updated 4 months ago
- Retired TrustedSec Capabilities☆225Updated last month
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆174Updated 6 months ago
- A collection of tools, scripts and personal research☆111Updated 4 months ago
- CIA UAC bypass implementation that utilizes elevated COM object to write to System32 and an auto-elevated process to execute as administr…☆174Updated 10 months ago
- Disconnected GPO Editor - A Group Policy Manager launcher to allow editing of domain GPOs from non-domain joined machines☆144Updated 2 months ago
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆300Updated last year
- ☆49Updated 3 months ago
- Slides & Code snippets for a workshop held @ x33fcon 2024☆236Updated 4 months ago
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆123Updated 5 months ago
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆123Updated last month
- Python utility that generates "imageless" QR codes in various formats☆99Updated 3 months ago
- ☆148Updated 7 months ago
- ☆153Updated 5 months ago
- Patching "signtool.exe" to accept expired certificates for code-signing.☆268Updated 3 months ago
- Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)☆162Updated last month
- Because AV evasion should be easy.☆306Updated 3 months ago
- ☆265Updated last year
- comprehensive .NET tool designed to extract and display detailed information about Windows Defender exclusions and Attack Surface Reducti…☆190Updated 5 months ago
- The CIA's Marble Framework is designed to allow for flexible and easy-to-use obfuscation when developing tools.☆289Updated 10 months ago