outflanknl / Excel4-DCOM
PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)
☆325Updated 6 years ago
Alternatives and similar repositories for Excel4-DCOM:
Users that are interested in Excel4-DCOM are comparing it to the libraries listed below
- DEPRECATED SharpRoast is a C# port of various PowerView's Kerberoasting functionality.☆252Updated 6 years ago
- Lateral Movement technique using DCOM and HTA☆233Updated 2 years ago
- lateral movement techniques that can be used during red team exercises☆271Updated 5 years ago
- The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification☆379Updated 5 years ago
- Assorted scripts and one off things☆268Updated 8 months ago
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆248Updated 4 years ago
- ☆348Updated 3 years ago
- A library for integrating communication channels with the Cobalt Strike External C2 server☆286Updated 7 years ago
- Recon-AD, an AD recon tool based on ADSI and reflective DLL’s☆327Updated 5 years ago
- Quick Malicious ClickOnceGenerator for Red Team☆249Updated 4 years ago
- Powershell script for enumerating vulnerable DCOM Applications☆257Updated 6 years ago
- PSAmsi is a tool for auditing and defeating AMSI signatures.☆390Updated 7 years ago
- ☆177Updated 6 years ago
- Evading WinDefender ATP credential-theft☆255Updated 5 years ago
- ☆272Updated 2 years ago
- This is a PowerShell Empire launcher PoC using PrintDemon and Faxhell.☆201Updated 4 years ago
- Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors☆154Updated 6 years ago
- CobaltStrike External C2 for Websockets☆193Updated 5 years ago
- ☆229Updated 6 years ago
- Auto-generate an HTaccess for payload delivery -- automatically pulls ips/nets/etc from known sandbox companies/sources that have been se…☆168Updated 4 years ago
- Neutering Sysmon via driver unload☆228Updated 2 years ago
- SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approa…☆291Updated 4 years ago
- Constrained Language Mode + AMSI bypass all in one☆157Updated 5 years ago
- Scripts for performing and detecting parent PID spoofing☆146Updated 4 years ago
- a tool to make it easy and fast to test various forms of injection☆173Updated 6 years ago
- An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.☆304Updated 2 years ago
- Aggressor scripts for phases of a pen test or red team assessment☆182Updated 8 months ago
- PoC of a VBA macro spawning a process with a spoofed parent and command line.☆381Updated 5 years ago
- Asynchronous Password Spraying Tool in C# for Windows Environments☆313Updated last year
- Create a minidump of the LSASS process from memory☆260Updated 2 years ago