Analysis and detection engineering for the BlueHammer Windows Defender local privilege escalation vulnerability. This repo includes bug fixes, 7 Sigma rules, 4 YARA rules, and MITRE ATT&CK-mapped technical report
☆89Apr 8, 2026Updated last month
Alternatives and similar repositories for BlueHammerFix
Users that are interested in BlueHammerFix are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- WebClientRelayUp - an universal no-fix local privilege escalation in domain-joined windows workstations in default configuration.☆85Apr 28, 2026Updated last month
- Automatically exported from code.google.com/p/lvdun☆13Dec 17, 2016Updated 9 years ago
- Sample scenes for appleseed☆10Sep 4, 2019Updated 6 years ago
- Oblivion-X is a high-risk script designed to modify system configurations on Samsung government-issued devices, disabling security featur…☆25Dec 16, 2024Updated last year
- A Super Mario Bros clone based on Infinite Mario.☆16Oct 29, 2019Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Documentation of Xbox One EXXX (E201, E105, etc...) error codes and their meaning, plus potential workarounds/repairs☆15Nov 30, 2023Updated 2 years ago
- AI-powered Windows Event Log analyzer that learns from your feedback. Uses Claude AI with RAG to detect suspicious activity, improve ac…☆37Dec 18, 2025Updated 5 months ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆109Apr 22, 2026Updated last month
- ☆15Mar 23, 2026Updated 2 months ago
- arm64 linux position-independent shellcode framework☆31Dec 12, 2025Updated 5 months ago
- Supernote - Excalidraw tools☆30Apr 24, 2025Updated last year
- A Crystal Palace shared library to resolve & perform syscalls☆62Oct 29, 2025Updated 7 months ago
- Sample x64dbg plugin to scan the stack during tracing.☆20Dec 19, 2016Updated 9 years ago
- OpenSource Woool Engine☆15Jul 21, 2015Updated 10 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Enable EFS service as low priv user (PE & BOF)☆21Jul 6, 2025Updated 11 months ago
- Exhaustive search and flexible filtering of Active Directory ACEs.☆78May 18, 2026Updated 2 weeks ago
- A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.☆160Apr 15, 2026Updated last month
- Evasion kit for Cobalt Strike☆30Jan 16, 2026Updated 4 months ago
- ☆51Feb 23, 2026Updated 3 months ago
- SharpExShell automates the DCOM lateral movment technique which abuses ActivateMicrosoftApp method of Excel application.☆75May 1, 2024Updated 2 years ago
- Extract Unique Word Lists From Wikipedia Database☆13May 27, 2020Updated 6 years ago
- Collection of danish base wordlists for cracking danish passwords (Hashcat, John the Ripper etc.)☆30Jan 11, 2023Updated 3 years ago
- pandaria_5.4.8_docker☆20Jul 28, 2025Updated 10 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Hardware ID Resetter for D2R bans.☆19Oct 10, 2021Updated 4 years ago
- CLI Tools to open, extract and mount FTK Imager's AccessData AD1 forensic images on linux.☆25May 27, 2025Updated last year
- Rainbow table generation & lookup tools.☆34Dec 17, 2025Updated 5 months ago
- Lateral movement with DCOM DLL hijacking☆178Jul 4, 2025Updated 11 months ago
- DLL injection with Microsoft detours☆24Dec 9, 2025Updated 5 months ago
- Scripts and a short guide for using them to tier an Active Directory. Made for BSides Copenhagen 2024☆40Oct 20, 2025Updated 7 months ago
- 传奇可编译源码 https://gitee.com/ambitiouscat/Mir☆19Dec 22, 2022Updated 3 years ago
- C#代码读取热血传奇wzl资源客户端的完美代码。(qq群821634331)我的qq:3292175891☆20Feb 11, 2018Updated 8 years ago
- Help red teams find opsec processes during engagements☆44Dec 7, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- IGE Mir2Engine Of Delphi Code☆23May 18, 2016Updated 10 years ago
- Chat, voice, and video, designed to self-host.☆55May 27, 2026Updated last week
- A cross platform Go library to work with Windows Security Descriptors☆42Apr 17, 2026Updated last month
- PowerShell collector for adding SCCM attack paths to BloodHound with OpenGraph☆89Apr 21, 2026Updated last month
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆139Jan 29, 2026Updated 4 months ago
- Find what egress ports are allowed☆47Nov 19, 2025Updated 6 months ago
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆181Updated this week