Ceri Coburn's repositories

SweetPotato

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

SharpBlock

A method of bypassing EDR's active projection DLL's by preventing entry point exection

BeaconEye

Hunts out CobaltStrike beacons and logs operator command output

ThreadlessInject

Threadless Process Injection using remote function hooking.

Language:C#License:MITStargazers:792Issues:11Issues:0

BOF.NET

A .NET Runtime for Cobalt Strike's Beacon Object Files

lsarelayx

NTLM relaying for Windows made easy

okta-terrify

Okta Verify and Okta FastPass Abuse Tool

DRSAT

Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domain joined machies

Language:C#License:Apache-2.0Stargazers:264Issues:3Issues:0

MinHook.NET

A C# port of the MinHook API hooking library

Language:C#License:BSD-3-ClauseStargazers:220Issues:6Issues:2

gssapi-abuse

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Language:PythonStargazers:175Issues:2Issues:0
Language:C#License:BSD-3-ClauseStargazers:162Issues:3Issues:0

dnMerge

A lightweight .NET assembly dependency merger that uses dnLib and 7zip's LZMA SDK for compressing dependant assemblies.

bittrex4j

Java library for accessing the Bittrex Web API's and Web Sockets

Language:JavaLicense:LGPL-3.0Stargazers:32Issues:12Issues:46

SQL-BOF

Library of BOFs to interact with SQL servers

Language:CLicense:GPL-2.0Stargazers:15Issues:0Issues:0

chlonium

Chromium Cookie import / export tool

Language:C#Stargazers:10Issues:0Issues:0

Rubeus

Trying to tame the three-headed dog.

Language:C#License:NOASSERTIONStargazers:9Issues:1Issues:0

InlineExecute-Assembly

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

Language:CStargazers:4Issues:1Issues:0

sandbox-attacksurface-analysis-tools

Set of tools to analyze Windows sandboxes for exposed attack surface.

Language:C#License:Apache-2.0Stargazers:3Issues:1Issues:0

nodebb-plugin-onesignal

Allows NodeBB to interface with the OneSignal service in order to provide push notifications via OneSignal, originally forked from nodebb-plugin-pushbullet

Language:JavaScriptLicense:MITStargazers:2Issues:3Issues:0

Certify

Active Directory certificate abuse.

Language:C#License:NOASSERTIONStargazers:1Issues:1Issues:0

impacket

Impacket is a collection of Python classes for working with network protocols.

Language:PythonLicense:NOASSERTIONStargazers:1Issues:2Issues:0

AceLdr

Cobalt Strike UDRL for memory scanner evasion.

Language:CLicense:MITStargazers:0Issues:1Issues:0

chisel

A fast TCP/UDP tunnel over HTTP

Language:GoLicense:MITStargazers:0Issues:1Issues:0

SharpHoundCommon

Common library used by SharpHound.

Language:C#License:GPL-3.0Stargazers:0Issues:1Issues:0

socks5

SOCKS5 server in Golang

Language:GoLicense:MITStargazers:0Issues:1Issues:0

SSH.NET

SSH.NET is a Secure Shell (SSH) library for .NET, optimized for parallelism.

Language:C#License:MITStargazers:0Issues:1Issues:0

titanldr-ng

A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge years ago.

Language:CStargazers:0Issues:0Issues:0