xpn / WAMBam
Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post
☆124Updated 2 years ago
Alternatives and similar repositories for WAMBam:
Users that are interested in WAMBam are comparing it to the libraries listed below
- ☆88Updated 2 years ago
- Implant drop-in for EDR testing☆135Updated last year
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- Section Mapping Process Injection (secinject): Cobalt Strike BOF☆92Updated 3 years ago
- Investigation about ACL abusing for Active Directory Certificate Services (AD CS)☆121Updated 3 years ago
- ☆92Updated 2 years ago
- ☆57Updated 3 years ago
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆52Updated 10 months ago
- Script to use SysWhispers2 direct system calls from Cobalt Strike BOFs☆123Updated 2 years ago
- Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post☆91Updated 2 years ago
- Collection of Beacon Object Files (BOFs) for shells and lols☆117Updated 3 years ago
- ☆142Updated 2 years ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Determine if the WebClient Service (WebDAV) is running on a remote system☆128Updated last year
- ☆62Updated 2 years ago
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆89Updated 10 months ago
- ☆139Updated 2 years ago
- ☆109Updated 4 months ago
- A basic meterpreter protocol stager using the libpeconv library by hasherezade for reflective loading☆83Updated 2 years ago
- ☆84Updated 3 years ago
- Simple BOF to read the protection level of a process☆115Updated last year
- A simple BOF that frees UDRLs☆117Updated 2 years ago
- A BOF to interact with COM objects associated with the Windows software firewall.☆102Updated 3 years ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆74Updated 2 years ago
- Lateral Movement via the .NET Profiler☆79Updated 4 months ago
- ☆106Updated 11 months ago
- Unchain AMSI by patching the provider’s unmonitored memory space☆89Updated 2 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆133Updated 6 months ago
- Lockless BOF☆70Updated last month
- A .NET Runtime for Cobalt Strike's Beacon Object Files☆66Updated 5 months ago