Hagrid29

Hagrid29

Geek Repo

Location:Hong Kong

Github PK Tool:Github PK Tool

Hagrid29's repositories

PELoader

PE loader with various shellcode injection techniques

DuplicateDump

Dumping LSASS with a duplicated handle from custom LSA plugin

RemotePatcher

Patch AMSI and ETW in remote process via direct syscall

Language:CStargazers:73Issues:3Issues:0

BYOVDKit

bring your own vulnerable driver

Language:C++Stargazers:55Issues:1Issues:0

AbuseAzureAPIPermissions

Abuse Azure API permissions for red teaming

Language:PowerShellStargazers:50Issues:1Issues:0

BOF-SprayAD

Cobalt Strike Beacon Object File (BOF) that uses LogonUserSSPI API to perform kerberos-based password spray

Language:CStargazers:40Issues:1Issues:0

herpaderply_hollowing

Herpaderply Hollowing - a PE injection technique, hybrid between Process Hollowing and Process Herpaderping

Language:CStargazers:38Issues:4Issues:0

BOF-DCOMPotato-PrintNotify

Cobalt Strike Beacon Object File (BOF) that obtain SYSTEM privilege with SeImpersonate privilege by passing a malicious IUnknwon object to DCOM call of PrintNotify.

Language:C++Stargazers:35Issues:1Issues:0

DumpAADSyncCreds

C# implementation of Get-AADIntSyncCredentials from AADInternals, which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.

CertifyKit

Active Directory certificate abuse

Language:C#Stargazers:25Issues:1Issues:0

BOF-CredUI

Cobalt Strike Beacon Object File (BOF) that uses CredUIPromptForWindowsCredentials API to invoke credential prompt

Language:CStargazers:19Issues:1Issues:0

BOF-RemoteRegSave

Cobalt Strike Beacon Object File (BOF) that uses RegConnectRegistryA + RegOpenKeyExA API to dump registry hives on remote computer

Language:CStargazers:11Issues:1Issues:0

DumpAADUserRPT

DumpAADUserRPT is C# implementation of Get-AADIntUserPRTToken from AADInternals which obtain Primary Refresh Token

Language:C#Stargazers:5Issues:0Issues:0

ForeScout-SecureConnector-EoP

Arbitrary File Delete in Forescout SecureConnector before 11.3.06.0063

Language:C++Stargazers:4Issues:1Issues:0

ReadWrite-DCOM

Perform directory listing, read and write file on remote computer via DCOM methods

Language:PowerShellStargazers:4Issues:2Issues:0