trustedsec / auto_SettingContent-msLinks
This is a quick POC for using the Matt Nelson (enigma0x3) technique for generating a malicious .SettingContent-ms extension type for remote code execution. This automates generating an HTA downloader and embeds it in the SettingContent-ms file for you and starts Apache.
☆54Updated 7 years ago
Alternatives and similar repositories for auto_SettingContent-ms
Users that are interested in auto_SettingContent-ms are comparing it to the libraries listed below
Sorting:
- Cobalt Strike Field Manual - A quick reference for Windows commands that can be accessed in a beacon console.☆65Updated 7 years ago
- Empire HTTP(S) C2 redirector setup script☆47Updated 7 years ago
- A C# implementation of the PowerShell Empire Agent☆73Updated 6 years ago
- ☆77Updated 7 years ago
- ☆83Updated 9 years ago
- A sample bot for Cobalt Strike 3☆22Updated 9 years ago
- ☆94Updated 6 years ago
- ☆41Updated 7 years ago
- Quick PoC I Wrote for Bypassing Next Gen AV Remotely for Pentesting☆41Updated 6 years ago
- C# Targeted Attack Reconnissance Tools☆122Updated 4 years ago
- InfoPath Phishing Repo Resource☆69Updated 7 years ago
- CACTUSTORCH: Payload Generation for Adversary Simulations☆76Updated 7 years ago
- When CactusTorch meets WebDavDelivery and obfuscation☆63Updated 7 years ago
- PowerAvails is a unit of collection of Powershell modules that help you get done many things☆118Updated 6 years ago
- A collection of PowerShell Modules for BloodHound/Empire Orchestration☆108Updated 7 years ago
- ☆58Updated 8 years ago
- Code for blogpost: https://outflank.nl/blog/2018/10/25/building-resilient-c2-infrastructues-using-dns-over-https/☆52Updated 6 years ago
- Powershell Persistence Locator☆66Updated 9 years ago
- Quickly Implement Mod-Rewrite in your infastructure☆83Updated 8 years ago
- AMSI bypass stager generator☆29Updated 6 years ago
- ☆110Updated 7 years ago
- Simple PowerShell Base64 encoder to avoid detection of your malicious payload☆81Updated 7 years ago
- A cobaltstrike script that integrates DDEAuto Attacks☆63Updated 7 years ago
- Includes 5 Known Application Whitelisting/ Application Control Bypass Techniques in One File.☆32Updated 9 years ago
- The PowerThIEf, an Internet Explorer Post Exploitation library☆130Updated 6 months ago
- Powershell script which will take any payload and put it in the a bat script which delivers the payload. The payload is delivered using e…☆52Updated last year
- Loads the AutoIt DLL and PowerShell assemblies into memory and executes the specified keystrokes☆62Updated 8 years ago
- Pypykatz agent implemented in .NET☆84Updated 6 years ago
- ☆94Updated 6 years ago
- Generates anti-sandbox analysis HTA files without payloads☆120Updated 8 years ago