funnybananas's repositories

kerbof

Kerboers BOFs - inspired and heavily adapted from nanorobeus and rubeus

Language:CStargazers:11Issues:0Issues:0

LayeredSyscall

Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows.

Language:CStargazers:1Issues:0Issues:0

StandIn

StandIn is a small .NET35/45 AD post-exploitation toolkit

Language:C#Stargazers:1Issues:0Issues:0

awesome-lists

Awesome Security lists for SOC/CERT/CTI

Language:PythonStargazers:0Issues:0Issues:0

BadBlood

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:0Issues:0

Beacon_Source

not a reverse-engineered version of the Cobalt Strike Beacon

Language:CStargazers:0Issues:0Issues:0

BOFs

Collection of Beacon Object Files

Language:CStargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

Cobalt-Strike

Various resources to enhance Cobalt Strike's functionality and its ability to evade antivirus/EDR detection

Language:C++License:MITStargazers:0Issues:0Issues:0

CS_Uploads_Tracker

Aggressor script add-in for CobaltStrike to track file uploads

License:GPL-3.0Stargazers:0Issues:0Issues:0

CVE-2023-46747-RCE

exploit for f5-big-ip RCE cve-2023-46747

Language:PythonStargazers:0Issues:0Issues:0

DefenderYara

Extracted Yara rules from Windows Defender mpavbase and mpasbase

Language:YARAStargazers:0Issues:0Issues:0

NimlineWhispers

A very proof-of-concept port of InlineWhispers for using syscalls in Nim projects.

Language:AssemblyStargazers:0Issues:0Issues:0
Language:C++Stargazers:0Issues:0Issues:0

DojoLoader

Generic PE loader for fast prototyping evasion techniques

License:Apache-2.0Stargazers:0Issues:0Issues:0

ghostwriting-2

A process injection technique using only thread context manipulation

Stargazers:0Issues:0Issues:0

GOAD

game of active directory

License:GPL-3.0Stargazers:0Issues:0Issues:0

import-owned-users-bloodhound

script to import owned users in bloodhound

Language:PythonStargazers:0Issues:0Issues:0

NimGetWindowClasses

Enumerates windows and returns the title (if any), PID, and Window Class Name.

Stargazers:0Issues:1Issues:0

nimview

A Nim/Webview based helper to create Desktop/Server applications with Nim/C/C++ and HTML/CSS

License:MITStargazers:0Issues:0Issues:0

Operational-Security-101

A repository of advice and guides to share with friends and family who are concerned about their safety during online activities and the security of their devices.

Stargazers:0Issues:0Issues:0

pyMetaTwin

Copy metadata and digital signatures information from one Windows executable to another using Wine on a non-Windows platform

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

SCShell

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Language:CStargazers:0Issues:0Issues:0

sleepmask-vs

A simple Sleepmask BOF example

Language:C++License:Apache-2.0Stargazers:0Issues:0Issues:0

SteppingStones

A Red Team Activity Hub

License:Apache-2.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0
Language:CStargazers:0Issues:0Issues:0

vim-config

A repository containing Vim configurations that set up specific development environments.

Language:Vim ScriptStargazers:0Issues:0Issues:0

Vundle.vim

Vundle, the plug-in manager for Vim

License:MITStargazers:0Issues:0Issues:0