tyranid / windows-security-internals
A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.
☆153Updated 10 months ago
Alternatives and similar repositories for windows-security-internals:
Users that are interested in windows-security-internals are comparing it to the libraries listed below
- A PoC of the ContainYourself research presented in DEFCON 31, which abuses the Windows containers framework to bypass EDRs.☆306Updated last year
- ☆296Updated 3 months ago
- ☆297Updated 3 months ago
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆343Updated 2 months ago
- ☆105Updated 7 months ago
- Collect Windows telemetry for Maldev☆297Updated last week
- Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting☆357Updated 2 years ago
- ☆375Updated 2 years ago
- ☆142Updated 3 weeks ago
- ☆154Updated 9 months ago
- .net config loader☆310Updated last year
- Find potential DLL Sideloads on your windows computer☆175Updated last month
- A collection of tools, scripts and personal research☆125Updated 7 months ago
- ☆185Updated last year
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆381Updated 6 months ago
- ☆176Updated last year
- A set of programs for analyzing common vulnerabilities in COM☆191Updated 5 months ago
- Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection☆274Updated 9 months ago
- ☆297Updated last year
- ☆112Updated last year
- A Visual Studio template used to create Cobalt Strike BOFs☆289Updated 3 years ago
- Tools for analyzing EDR agents☆219Updated 8 months ago
- Dump the memory of any PPL with a Userland exploit chain☆332Updated last year
- ☆248Updated last year
- ShellWasp is a tool to help build shellcode that utilizes Windows syscalls, while overcoming the portability problem associated with Wind…☆165Updated last year
- ☆142Updated 2 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆188Updated last month
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆333Updated last week
- Hiding shellcode in plain sight within a large memory region. Inspired by technique used by Raspberry Robin's Roshtyak☆196Updated 2 years ago