wietze / Invoke-ArgFuscatorLinks
Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native executables.
☆261Updated 9 months ago
Alternatives and similar repositories for Invoke-ArgFuscator
Users that are interested in Invoke-ArgFuscator are comparing it to the libraries listed below
Sorting:
- Find potential DLL Sideloads on your windows computer☆218Updated last year
- .NET post-exploitation toolkit for Active Directory reconnaissance and exploitation☆400Updated 6 months ago
- Tool designed to find folder exclusions using Windows Defender using command line utility MpCmdRun.exe as a low privileged user, without …☆230Updated last year
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆419Updated 4 months ago
- ☆235Updated 8 months ago
- lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection☆255Updated 2 weeks ago
- Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence☆422Updated 3 months ago
- SoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.☆260Updated 11 months ago
- PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirector…☆398Updated 3 weeks ago
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆382Updated 4 months ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆358Updated 2 weeks ago
- NukeAMSI is a powerful tool designed to neutralize the Antimalware Scan Interface (AMSI) in Windows environments.☆173Updated last month
- ☆334Updated 5 months ago
- 🔥📜 Forbidden collection of Red Team sorcery 📜🔥☆331Updated last week
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆354Updated last month
- Weaponizing DCOM for NTLM Authentication Coercions☆275Updated 7 months ago
- MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.☆336Updated last year
- Execute commands interactively on remote Windows machines using the WinRM protocol☆323Updated 2 weeks ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆357Updated last month
- Windows protocol library, including SMB and RPC implementations, among others.☆609Updated 3 weeks ago
- ☆230Updated 8 months ago
- A BloodHound collector for Microsoft Configuration Manager☆363Updated 7 months ago
- ☆246Updated last year
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆432Updated 7 months ago
- Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection☆323Updated last year
- ☆290Updated 2 years ago
- psexecsvc - a python implementation of PSExec's native service implementation☆235Updated last year
- ☆159Updated 10 months ago
- Python implementation of GhostPack's Seatbelt situational awareness tool☆270Updated last year
- A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts☆167Updated 7 months ago