t94j0 / sddl_pyLinks
Parse SDDL strings
☆36Updated last year
Alternatives and similar repositories for sddl_py
Users that are interested in sddl_py are comparing it to the libraries listed below
Sorting:
- Click Once + App Domain☆64Updated last year
- Python module for running BOFs☆74Updated 2 years ago
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆88Updated 2 years ago
- A VSCode devcontainer for development of COFF files with batteries included.☆49Updated 2 years ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆91Updated 4 months ago
- ☆39Updated 3 years ago
- A care package of useful bofs for red team engagments☆55Updated 11 months ago
- Parser and reconciliation tooling for large Active Directory environments.☆33Updated 9 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆41Updated 2 years ago
- a simple poc showcasing the ability of an admin to suspend EDR's protected processes , making it useless☆39Updated last year
- RPC to WebClient startup☆52Updated 3 months ago
- ☆88Updated 3 years ago
- Lateral Movement via the .NET Profiler☆84Updated last year
- Lockless BOF☆79Updated 6 months ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆34Updated 2 years ago
- An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities☆63Updated 3 years ago
- Bunch of BOF files☆36Updated 4 months ago
- ☆33Updated last year
- Determine if the WebClient Service (WebDAV) is running on a remote system☆21Updated last year
- GhostLoader - AppDomainManager - Injection - 攻壳机动队☆52Updated 5 years ago
- Sniffing files generator☆59Updated 8 months ago
- C# version of NTLMRawUnHide☆72Updated 3 years ago
- Local SYSTEM auth trigger for relaying - X☆153Updated 3 months ago
- Example of using Sleep to create better named pipes.☆41Updated 2 years ago
- ☆50Updated 4 months ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆91Updated 2 years ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆129Updated 2 years ago
- PoC script to demonstrate collection of SCCM attack paths that can be viewed in BH with OpenGraph☆24Updated 3 months ago
- Command Augmentation support for BOFs and .NET assemblies across agents☆36Updated 5 months ago
- A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading☆84Updated 3 years ago