Ceri Coburn's repositories

SweetPotato

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

SharpBlock

A method of bypassing EDR's active projection DLL's by preventing entry point exection

BeaconEye

Hunts out CobaltStrike beacons and logs operator command output

ThreadlessInject

Threadless Process Injection using remote function hooking.

Language:C#License:MITStargazers:674Issues:8Issues:0

BOF.NET

A .NET Runtime for Cobalt Strike's Beacon Object Files

lsarelayx

NTLM relaying for Windows made easy

MirrorDump

Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory

okta-terrify

Okta Verify and Okta FastPass Abuse Tool

MinHook.NET

A C# port of the MinHook API hooking library

Language:C#License:BSD-3-ClauseStargazers:195Issues:5Issues:2

gssapi-abuse

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Language:PythonStargazers:128Issues:2Issues:0

dnMerge

A lightweight .NET assembly dependency merger that uses dnLib and 7zip's LZMA SDK for compressing dependant assemblies.

PinSwipe

Smart Card PIN swiping DLL

Language:CStargazers:71Issues:3Issues:0

bittrex4j

Java library for accessing the Bittrex Web API's and Web Sockets

Language:JavaLicense:LGPL-3.0Stargazers:31Issues:13Issues:46

Rubeus

Trying to tame the three-headed dog.

Language:C#License:NOASSERTIONStargazers:8Issues:2Issues:0

InlineExecute-Assembly

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module

Language:CStargazers:4Issues:1Issues:0

nmap

Nmap - the Network Mapper. Github mirror of official SVN repository.

Language:LuaLicense:NOASSERTIONStargazers:3Issues:2Issues:0

nodebb-plugin-onesignal

Allows NodeBB to interface with the OneSignal service in order to provide push notifications via OneSignal, originally forked from nodebb-plugin-pushbullet

Language:JavaScriptLicense:MITStargazers:2Issues:4Issues:0

Certify

Active Directory certificate abuse.

Language:C#License:NOASSERTIONStargazers:1Issues:1Issues:0

impacket

Impacket is a collection of Python classes for working with network protocols.

Language:PythonLicense:NOASSERTIONStargazers:1Issues:2Issues:0

sandbox-attacksurface-analysis-tools

Set of tools to analyze Windows sandboxes for exposed attack surface.

Language:C#License:Apache-2.0Stargazers:1Issues:1Issues:0

AceLdr

Cobalt Strike UDRL for memory scanner evasion.

Language:CLicense:MITStargazers:0Issues:1Issues:0

bndutil

Provides blocknode-specific convenience functions and types

Language:GoLicense:ISCStargazers:0Issues:3Issues:0

chisel

A fast TCP/UDP tunnel over HTTP

Language:GoLicense:MITStargazers:0Issues:1Issues:0

SharpHoundCommon

Common library used by SharpHound.

Language:C#License:GPL-3.0Stargazers:0Issues:1Issues:0

socks5

SOCKS5 server in Golang

Language:GoLicense:MITStargazers:0Issues:1Issues:0

SSH.NET

SSH.NET is a Secure Shell (SSH) library for .NET, optimized for parallelism.

Language:C#License:MITStargazers:0Issues:1Issues:0