offensive-actions / release-tampering-pocsView external linksLinks
Proof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec Europe 2025
☆78Sep 16, 2025Updated 5 months ago
Alternatives and similar repositories for release-tampering-pocs
Users that are interested in release-tampering-pocs are comparing it to the libraries listed below
Sorting:
- CLI version of NetworkMiner (https://www.netresec.com/?page=NetworkMiner)☆13Dec 1, 2025Updated 2 months ago
- Static analysis for llvm☆20Mar 31, 2015Updated 10 years ago
- ☆18Oct 28, 2025Updated 3 months ago
- Inter-procedural analysis framework and dependency/information-flow analysis for LLVM☆19Mar 2, 2013Updated 12 years ago
- AWS X-Ray for Covert Command & Control☆45Oct 13, 2025Updated 4 months ago
- GitHub Action to alert on security patches before the CVE drops.☆34Feb 7, 2026Updated last week
- Living Under the Land on Linux ~ Bsides Belfast/Vienna 2025☆37Nov 22, 2025Updated 2 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Aug 13, 2024Updated last year
- A tool to identify and remediate common misconfigurations in Active Directory Certificate Services☆17Jan 13, 2024Updated 2 years ago
- A curated collection of Living off the Land (LotL) attack demonstrations where trusted binaries go rogue, because if it didn’t launch cal…☆35Jan 7, 2026Updated last month
- By manipulating LSASS memory flags like UseLogonCredential and IsCredGuardEnabled, this repo demonstrates how Credential Guard can be byp…☆14May 25, 2025Updated 8 months ago
- Decrypt GlobalProtect configuration and cookie files.☆158Sep 10, 2024Updated last year
- A frightfully intelligent algorithmic trading automaton of noble birth. Sir Reginald's prime directive: to acquire undervalued assets pos…☆40Sep 18, 2025Updated 4 months ago
- 🔍 SubWatch – Automated Subdomain Monitoring Script☆40Jun 13, 2025Updated 8 months ago
- ☆28Jan 10, 2024Updated 2 years ago
- (MeetC2 a.k.a Meeting C2) - A framework abusing Google Calendar APIs.☆132Sep 4, 2025Updated 5 months ago
- Some of my custom "tools".☆28Feb 21, 2022Updated 3 years ago
- Crane POAM Automation Tool (C-PAT™)☆15Updated this week
- ☆26Jun 2, 2022Updated 3 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆67Mar 27, 2023Updated 2 years ago
- Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org☆124Nov 9, 2022Updated 3 years ago
- ☆30Mar 2, 2023Updated 2 years ago
- Additional materials for RootedCON 2015 Apache Struts talk☆30Mar 6, 2015Updated 10 years ago
- ☆31Mar 21, 2023Updated 2 years ago
- ☆10Feb 9, 2026Updated last week
- time-based user enum via Basic Auth in Azure against Autodiscover☆33Oct 3, 2024Updated last year
- ☆13Aug 5, 2025Updated 6 months ago
- CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)☆45Oct 16, 2024Updated last year
- Burp extension to decode NTLM SSP headers and extract domain/host information☆31Mar 11, 2021Updated 4 years ago
- A proof-of-concept shellcode loader that leverages AI/ML face recognition models to verify the identity of a user on a target system☆40Oct 30, 2024Updated last year
- Linux Process Injection via Seccomp Notifier☆81Dec 9, 2025Updated 2 months ago
- ProXBBE (Protocol eXtraction By Binary Execution)☆31Sep 21, 2017Updated 8 years ago
- At some point, I learned about a method to perform a binary search on a file in order to identify its AV signature and change it to bypas…☆36Aug 3, 2020Updated 5 years ago
- Libary for using OScam dvbapi within various applications. This Plugin is not for usage, only experiment and research.☆11Jan 4, 2024Updated 2 years ago
- ☆15Sep 4, 2024Updated last year
- k8s ConfigMaps and Secrets Usage.☆11Jan 24, 2025Updated last year
- Notes for the PJPT exam!☆14Aug 8, 2024Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆258Updated this week
- Execute commands in other Sessions☆91Jul 29, 2024Updated last year