mattifestation / WMI_Backdoor
A PoC WMI backdoor presented at Black Hat 2015
☆273Updated 9 years ago
Alternatives and similar repositories for WMI_Backdoor:
Users that are interested in WMI_Backdoor are comparing it to the libraries listed below
- A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.☆320Updated 7 years ago
- Netview enumerates systems using WinAPI calls☆294Updated 3 years ago
- Tater is a PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesec☆449Updated 8 years ago
- PowerShell Empire Web Interface☆330Updated last year
- This repo is for WMIOps, a powershell script which uses WMI for various purposes across a network.☆383Updated 9 months ago
- Powershell VNC injector☆336Updated 4 years ago
- Powershell module to assist in attacking Exchange/Outlook Web Access☆180Updated 8 years ago
- ☆164Updated 9 years ago
- PowerShell Scripts focused on Post-Exploitation Capabilities☆318Updated 7 years ago
- ObfuscatedEmpire is a fork of Empire with Invoke-Obfuscation integrated directly into it's functionality.☆228Updated 7 years ago
- Not PowerShell☆445Updated 8 years ago
- A script to test an RDP host for sticky keys and utilman backdoor.☆259Updated 8 years ago
- Use powershell to list the RDP Connections History of logged-in users or all users☆262Updated 4 years ago
- ☆272Updated 2 years ago
- A PowerShell example of the Windows zero day priv esc☆326Updated 6 years ago
- Uses Invoke-Shellcode to execute a payload and persist on the system.☆113Updated 8 years ago
- morphHTA - Morphing Cobalt Strike's evil.HTA☆521Updated 2 years ago
- An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.☆303Updated 2 years ago
- SprayWMI is an easy way to get mass shells on systems that support WMI. Much more effective than PSEXEC as it does not leave remnants on …☆253Updated 9 years ago
- Lazykatz is an automation developed to extract credentials from remote targets protected with AV and/or application whitelisting software…☆198Updated 7 years ago
- Remote Recon and Collection☆449Updated 7 years ago
- CScriptShell, a Powershell Host running within cscript.exe☆160Updated 8 years ago
- Forward local or remote tcp ports through SMB pipes.☆295Updated 4 years ago
- This version of PowerUp is now unsupported. See https://github.com/Veil-Framework/PowerTools/tree/master/PowerUp for the most current ver…☆244Updated 7 years ago
- A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.☆170Updated last month
- Port of eternal blue exploits to powershell☆150Updated 7 years ago
- A WebDAV PROPFIND C2 tool☆119Updated 5 years ago
- initial commit☆172Updated 6 years ago
- This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows O…☆302Updated 8 years ago
- Meterpreter_Payload_Detection.exe tool for detecting Meterpreter in memory like IPS-IDS and Forensics tool☆162Updated last year