roobixx / EventLogForRedTeams
Simple PoC from Malicious Payload Injection from Windows Event Log Entry
☆27Updated 2 years ago
Alternatives and similar repositories for EventLogForRedTeams:
Users that are interested in EventLogForRedTeams are comparing it to the libraries listed below
- ☆43Updated 7 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆41Updated 4 months ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 3 years ago
- Leveraging AWS Lambda Function URLs for C2 Redirection☆26Updated last year
- ☆37Updated 9 months ago
- A collection of tools Neil and Andy have been working on released in one place and interlinked with previous tools☆87Updated last year
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆120Updated 3 years ago
- ☆71Updated last year
- A small go tool to upload JSON files to the BloodHound community edition API☆30Updated 8 months ago
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆85Updated 9 months ago
- Extra cmdlets to help with quering security related information from Azure☆13Updated 5 months ago
- Federated Office365 user enumeration based on correlated response trend analysis☆48Updated 2 years ago
- Slide decks and/or materials from conference presentations☆55Updated 2 years ago
- Living Off the Foreign Land setup scripts☆64Updated last month
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Small utility to chunk up a large BloodHound JSON file into smaller files for importing.☆92Updated last year
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- Get Fine Grained Password Policy☆67Updated 9 months ago
- Living off the land searches for explorer and sharepoint☆56Updated 3 months ago
- Bypass AMSI By Dividing files into multiple smaller files☆45Updated 2 years ago
- My BloodHound custom queries☆23Updated 2 years ago
- Lateral Movement☆122Updated last year
- Updated version of PowerDNS by @domchell. Adds support for transfers over DNS A records and a few other useful features.☆82Updated last year
- ☆56Updated 3 years ago
- Abuse Azure API permissions for red teaming☆61Updated 2 years ago
- C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps☆135Updated 6 months ago
- ☆43Updated 3 weeks ago
- A small script that automates Entra ID persistence with Windows Hello For Business key☆53Updated this week
- Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level☆25Updated 2 years ago