nmantani / PS-MOTW
PS-MOTW: PowerShell scripts to set / show / remove MOTW (Mark of the Web)
☆34Updated last year
Alternatives and similar repositories for PS-MOTW:
Users that are interested in PS-MOTW are comparing it to the libraries listed below
- ☆27Updated last year
- BOF for C2 framework☆40Updated 2 months ago
- ☆28Updated 4 months ago
- Extension functionality for the NightHawk operator client☆26Updated last year
- Parse SDDL strings☆35Updated 9 months ago
- Read ETW Provider events. Inspired by ETWExplorer by Pavel Yosifovich☆14Updated 6 months ago
- ☆45Updated last year
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated 6 months ago
- ☆68Updated 5 months ago
- Creation and removal of Defender path exclusions and exceptions in C#.☆30Updated last year
- ☆31Updated last month
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆38Updated last year
- ☆47Updated last year
- GetSystem-LCI is a PowerShell script to escalate privileges from Administrator to NT AUTHORITY\SYSTEM by abusing LanguageComponentsInstal…☆29Updated last month
- Just another ntdll unhooking using Parun's Fart technique☆73Updated last year
- ☆42Updated 6 months ago
- This project is an EDRSandblast fork, adding some features and custom pieces of code.☆21Updated last year
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆45Updated 10 months ago
- DirSync is a simple proof of concept PowerShell module to demonstrate the impact of delegating DS-Replication-Get-Changes and DS-Replicat…☆27Updated last year
- ☆45Updated 2 months ago
- A C# port of https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80☆18Updated last year
- Dump LSASS by spoofing command line arguments to procdump.☆19Updated 2 months ago
- Small tool to play with IOCs caused by Imageload events☆42Updated last year
- ☆58Updated last year
- These are the slide decks and source code for Brute Ratel Seminar conducted on 24th August 2023. The youtube video for the seminar can be…☆19Updated last year
- Test AMSI Provider implementation in C#☆29Updated last month
- Lifetime AMSI bypass.☆35Updated 6 months ago
- PowerShell Implementation of ADFSDump to assist with GoldenSAML☆31Updated 7 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆24Updated 4 months ago
- ECC Public Key Cryptography☆36Updated last year