H*s*m (WazeHell)

WazeHell

Geek Repo

Company:@halbornlabs

Twitter:@safe_buffer

Github PK Tool:Github PK Tool

H*s*m's starred repositories

RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Language:PythonLicense:BSD-3-ClauseStargazers:2302Issues:81Issues:140

EVTX-ATTACK-SAMPLES

Windows Events Attack Samples

Language:HTMLLicense:GPL-3.0Stargazers:2138Issues:144Issues:11

UltimateAppLockerByPassList

The goal of this repository is to document the most common techniques to bypass AppLocker.

SysWhispers

AV/EDR evasion via direct system calls.

Language:AssemblyLicense:Apache-2.0Stargazers:1709Issues:60Issues:8

LTESniffer

An Open-source LTE Downlink/Uplink Eavesdropper

DotNetToJScript

A tool to create a JScript file which loads a .NET v2 assembly from memory.

Language:C#License:GPL-3.0Stargazers:1184Issues:46Issues:13

CS-Situational-Awareness-BOF

Situational Awareness commands implemented using Beacon Object Files

Language:CLicense:GPL-2.0Stargazers:1144Issues:37Issues:33

SharpGPOAbuse

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.

Cobalt-Strike-CheatSheet

Some notes and examples for cobalt strike's functionality

Alaris

A protective and Low Level Shellcode Loader that defeats modern EDR systems.

Language:CLicense:Apache-2.0Stargazers:832Issues:23Issues:16

capsulecorp-pentest

Vagrant VirtualBox environment for conducting an internal network penetration test

LAPSToolkit

Tool to audit and attack LAPS environments

PowerShell-AD-Recon

PowerShell Scripts I find useful

DripLoader

Evasive shellcode loader for bypassing event-based injection detection (PoC)

Language:C++License:MITStargazers:687Issues:15Issues:2

cobalt_strike_extension_kit

Attempting to be an all in one repo for others' userful aggressor scripts as well as things we've found useful during Red Team Operations.

Language:PowerShellLicense:GPL-3.0Stargazers:645Issues:30Issues:4

SharpSphere

.NET Project for Attacking vCenter

EXCELntDonut

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Language:PythonLicense:GPL-3.0Stargazers:493Issues:20Issues:11

SharpAllTheThings

The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.

SysmonSearch

Investigate suspicious activity by visualizing Sysmon's event log

Language:JavaScriptLicense:NOASSERTIONStargazers:410Issues:44Issues:13

SharpBypassUAC

C# tool for UAC bypasses

Language:C#License:MITStargazers:392Issues:10Issues:1

module_overloading

A more stealthy variant of "DLL hollowing"

FuzzFactory

Domain-Specific Fuzzing with Waypoints

PSReflect

Easily define in-memory enums, structs, and Win32 functions in PowerShell

Language:PowerShellLicense:BSD-3-ClauseStargazers:214Issues:21Issues:11

SharpCloud

Simple C# for checking for the existence of credential files related to AWS, Microsoft Azure, and Google Compute.

Language:C#License:BSD-3-ClauseStargazers:159Issues:11Issues:0

kirlangic-ttf-fuzzer

TrueType Font Fuzzer

Language:PythonStargazers:53Issues:11Issues:0

CAFA

CAFA: A Checksum-Aware Fuzzing Assistant For More Coverage

Language:HTMLStargazers:31Issues:0Issues:0

jekyll-theme-hydure

A concise two-column blog theme for Jekyll.

Language:SCSSLicense:MITStargazers:30Issues:2Issues:2

exchange-test-environment

A Vagrantfile and Ansible playbook that can be used to setup test environment with an Exchange server host

isweb

Fast & Lightweight HTTP/s checker

Language:C++Stargazers:8Issues:2Issues:0