robwillisinfo / Invoke-Decoder
Invoke-Decoder – A PowerShell script to decode/deobfuscate malware samples
☆20Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for Invoke-Decoder
- ProcDot Malware Sandbox☆21Updated 6 years ago
- Use smb2 protocol to detect remote computer os version, support win7/server2008-win10/server2019☆59Updated 3 years ago
- RemotePSpy provides live monitoring of remote PowerShell sessions, which is particularly useful for older (pre-5.0) versions of PowerShel…☆18Updated 4 years ago
- RID Hijacking Proof of Concept script by Kevin Joyce☆15Updated 6 years ago
- Simple C2 over the Trello API☆37Updated last year
- Retrieve the IIS Application Pool Credentials. Relies on the WebAdministration PowerShell Module.☆13Updated 6 years ago
- Tool to manage user privileges☆28Updated 5 years ago
- A library to parse, modify, and implement Malleable C2 profiles☆21Updated 5 years ago
- Babel-Shellfish deobfuscates and scans Powershell scripts on real-time right before each line execution.☆41Updated 6 years ago
- Spin up a reverse proxy quickly on Heroku☆13Updated 3 years ago
- Automation Capable Multi Search 64 Bit Windows Memory Scanner☆28Updated 3 years ago
- Log converter from CS log to Ghostwriter CSV☆29Updated 3 years ago
- AppXSVC Service race condition - privilege escalation☆27Updated 5 years ago
- Experiments on the Windows Internals☆30Updated 5 years ago
- C# Situational Awareness Script☆34Updated 5 years ago
- Scripts to automate standing up apache2 with mod_rewrite in front of C2 servers.☆46Updated 3 years ago
- A set of commands to bypass Defender (and some other AVs)☆18Updated 5 years ago
- A Canary which fires when uninstalled☆34Updated 3 years ago
- Remote process dumping automation. Use it to dump Windows credentials remotely and extract clear text with Mimikatz offline☆35Updated 4 years ago
- ☆12Updated 3 years ago
- Miscellaneous PowerShell scripts for red team activities☆16Updated last week
- Extracts Azure authentication tokens from PowerShell process minidumps.☆23Updated last year
- Run Managed Assemblies with RunDll☆16Updated 6 years ago
- A cross platform tool for verifying credentials and executing single commands☆32Updated 5 years ago
- ☆14Updated 7 months ago
- ☆15Updated 4 years ago
- 2 ways of Password Filter DLL to record the plaintext password☆62Updated 3 years ago
- Ingests logs/dbs from cobalt and empire and outputs an excel report with activity, sessions, and credentials☆20Updated 3 years ago