r4wd3r / RID-Hijacking
Windows RID Hijacking persistence technique
☆164Updated 2 years ago
Related projects: ⓘ
- Obfuscated Penetration Testing PowerShell scripts☆131Updated 8 years ago
- ☆78Updated 7 years ago
- Powershell script for enumerating vulnerable DCOM Applications☆250Updated 5 years ago
- Various Cheat Sheets☆179Updated 3 years ago
- Quick Malicious ClickOnceGenerator for Red Team☆244Updated 3 years ago
- ☆230Updated 6 years ago
- Assorted scripts and one off things☆259Updated last month
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆105Updated 4 years ago
- Lateral Movement technique using DCOM and HTA☆228Updated last year
- ☆251Updated 2 years ago
- An Insider Threat Toolkit☆149Updated 5 years ago
- How To Execute Shellcode via HTA☆135Updated 6 years ago
- Misc. PowerShell scripts☆115Updated 8 years ago
- Presentation material presented by Outflank team members at public events.☆177Updated 3 months ago
- lateral movement techniques that can be used during red team exercises☆265Updated 4 years ago
- DLL Generator for side loading attack☆165Updated 5 years ago
- PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)☆321Updated 5 years ago
- GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects☆244Updated 3 years ago
- Some .ps1 scripts for pentesting☆131Updated 3 years ago
- Powershell function to pull the local admin passwords from LDAP, stored there by LAPS.☆114Updated 4 years ago
- SPF are not as strong as you may think. Red Team tool to send email on behalf of your target corp☆132Updated 3 years ago
- The PowerThIEf, an Internet Explorer Post Exploitation library☆130Updated 6 years ago
- ☆214Updated this week
- Uses Invoke-Shellcode to execute a payload and persist on the system.☆111Updated 7 years ago
- Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to…☆170Updated last year
- In case you didn't now how to restore the user password after a password reset (get the previous hash with DCSync)☆161Updated 7 years ago
- Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors☆147Updated 5 years ago
- Toolset for research malware and Cobalt Strike beacons☆205Updated last year
- PSAmsi is a tool for auditing and defeating AMSI signatures.☆386Updated 6 years ago
- ObfuscatedEmpire is a fork of Empire with Invoke-Obfuscation integrated directly into it's functionality.☆229Updated 6 years ago