James Yeung's repositories

CS-BOFs

Collection of CobaltStrike beacon object files

Language:CStargazers:1Issues:0Issues:0

CS-Situational-Awareness-BOF

Situational Awareness commands implemented using Beacon Object Files

Language:CLicense:GPL-2.0Stargazers:1Issues:0Issues:0

CVE-2023-22809-sudoedit-privesc

A script to automate privilege escalation with CVE-2023-22809 vulnerability

Stargazers:1Issues:0Issues:0

frida-dexdump

A frida tool to dump dex in memory to support security engineers analyzing malware.

License:GPL-3.0Stargazers:1Issues:0Issues:0

Proxy-Function-Calls-For-ETwTI

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

License:GPL-3.0Stargazers:1Issues:0Issues:0

APCLdr

Payload Loader With Evasion Features

License:MITStargazers:0Issues:0Issues:0

ASRenum-BOF

Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations

Stargazers:0Issues:0Issues:0

BackupOperatorToDA

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

Language:C++Stargazers:0Issues:0Issues:0

C2-Tool-Collection

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Language:CStargazers:0Issues:0Issues:0

CobaltWhispers

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection, persistence and more, leveraging direct syscalls (SysWhispers2) to bypass EDR/AV

License:MITStargazers:0Issues:0Issues:0

Cortex-XDR-Config-Extractor

Cortex XDR Config Extractor

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

Dirty-Vanity

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass-28417

Language:CStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

evilgophish

evilginx2 + gophish

License:GPL-3.0Stargazers:0Issues:0Issues:0

File-Smuggling

HTML smuggling is not an evil, it can be useful

Language:HTMLStargazers:0Issues:0Issues:0

FlavorTown

Various ways to execute shellcode

Language:C#License:BSD-3-ClauseStargazers:0Issues:0Issues:0

Inline-Execute-PE

Execute unmanaged Windows executables in CobaltStrike Beacons

Language:CLicense:Apache-2.0Stargazers:0Issues:0Issues:0

Interceptor

Interceptor is a kernel driver focused on tampering with EDR/AV solutions in kernel space

License:GPL-3.0Stargazers:0Issues:0Issues:0

nanorobeus

COFF file (BOF) for managing Kerberos tickets.

Language:CStargazers:0Issues:0Issues:0

OBFShellcode

Just a little dev time exploring other avenues to hide shellcode, I personally tried this with actual payloads and it did not do the job, for some odd reason calc popped though. This is actually garbage do not use this, no clue why I am posting this lol.

Stargazers:0Issues:0Issues:0

OneRuleToRuleThemStill

A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule

Stargazers:0Issues:0Issues:0

ProtectMyTooling

Multi-Packer allowing to daisy-chain over 29 packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.

Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

Proxy-DLL-Loads

The code is a pingback to the Dark Vortex blog:

License:GPL-3.0Stargazers:0Issues:0Issues:0

Red-Lambda

Leveraging AWS Lambda Function URLs for C2 Redirection

Stargazers:0Issues:0Issues:0

red-team-scripts

A collection of red teaming and adversary emulation related tools, scripts, techniques, notes, etc

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

reFlutter

Flutter Reverse Engineering Framework

License:GPL-3.0Stargazers:0Issues:0Issues:0

RToolZ

A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.

Stargazers:0Issues:0Issues:0
Language:CLicense:MITStargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0