sidaf / moonshine
☆69Updated last year
Alternatives and similar repositories for moonshine:
Users that are interested in moonshine are comparing it to the libraries listed below
- Living Off the Foreign Land setup scripts☆67Updated 2 months ago
- ☆88Updated 2 years ago
- Slide decks and/or materials from conference presentations☆56Updated 2 years ago
- Microsoft Graph API post-exploitation toolkit☆94Updated 9 months ago
- Simple EDR that injects a DLL into a process to place a hook on specific Windows API☆90Updated last year
- ☆48Updated last year
- ☆50Updated 6 months ago
- ☆116Updated 3 years ago
- Example code samples from our ScriptBlock Smuggling Blog post☆90Updated 10 months ago
- ☆110Updated 5 months ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆38Updated 9 months ago
- Your Skyfall Infrastructure Pack☆67Updated last week
- ☆71Updated last year
- Scan your computer for known vulnerable and known malicious Windows drivers using loldrivers.io☆82Updated last year
- Automatically create an operation log of your shell! Supports Linux (Bash/Zsh) and Windows (PowerShell/CMD).☆32Updated 2 months ago
- Enumerate information from NTLM authentication enabled web endpoints 🔎☆35Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆81Updated 2 years ago
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆76Updated last year
- Two in one, patch lifetime powershell console, no more etw and amsi!☆88Updated last week
- ☆59Updated last year
- Info related to the Outflank training: Microsoft Office Offensive Tradecraft☆52Updated 11 months ago
- ☆44Updated 10 months ago
- ☆41Updated 10 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 8 months ago
- ☆74Updated 9 months ago
- a tiny program to consume from ETW providers for research☆47Updated 4 months ago
- BOF to decrypt Signal Desktop chat logs☆65Updated 2 months ago
- A BOF to enumerate system process, their protection levels, and more.☆116Updated 5 months ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated 2 years ago
- Small Python tool to do DLL Sideloading (and consequently, other DLL attacks).☆56Updated 2 years ago