monoxgas / FlyingAFalseFlag
Slides and Code for the BHUSA 2019 talk: Flying a False Flag
☆227Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for FlyingAFalseFlag
- lateral movement techniques that can be used during red team exercises☆265Updated 4 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆105Updated 5 years ago
- Parse NTLM challenge messages over HTTP and SMB☆143Updated 2 years ago
- Domain user enumeration tool☆212Updated last year
- Lateral Movement technique using DCOM and HTA☆229Updated 2 years ago
- Powershell script for enumerating vulnerable DCOM Applications☆254Updated 5 years ago
- Auto-generate an HTaccess for payload delivery -- automatically pulls ips/nets/etc from known sandbox companies/sources that have been se…☆167Updated 4 years ago
- A list of files / paths to probe when arbitrary files can be read on a Microsoft Windows operating system☆199Updated last year
- A library for integrating communication channels with the Cobalt Strike External C2 server☆281Updated 7 years ago
- An Insider Threat Toolkit☆149Updated 5 years ago
- A HTA shell to assist with breakout assessments.☆112Updated 3 years ago
- Python api for usage with cobalt strike's External C2 specification☆225Updated last year
- Slides from my talk in "Hackinparis" 2019 edition☆89Updated 5 years ago
- CobaltStrike External C2 for Websockets☆194Updated 5 years ago
- Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)☆140Updated 7 years ago
- ntlm relay attack to Exchange Web Services☆328Updated 6 years ago
- ☆189Updated 4 years ago
- BlueHatIL 2020 - Staying # and Bringing Covert Injection Tradecraft to .NET☆143Updated 4 years ago
- The PowerThIEf, an Internet Explorer Post Exploitation library☆130Updated 6 years ago
- Quick Malicious ClickOnceGenerator for Red Team☆246Updated 3 years ago
- Toolset for research malware and Cobalt Strike beacons☆206Updated last year
- An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.☆301Updated 2 years ago
- Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors☆147Updated 5 years ago
- ☆233Updated 5 years ago
- BlueKeep scanner supporting NLA☆167Updated 5 years ago
- Recon-AD, an AD recon tool based on ADSI and reflective DLL’s☆316Updated 5 years ago
- A Powershell implementation of PrivExchange designed to run under the current user's context☆123Updated 5 years ago
- Powershell module to get the NetNTLMv2 hash of the current user☆92Updated 2 years ago