Cody Thomas's repositories

Mythic

A collaborative, multi-platform, red teaming framework

Language:JavaScriptLicense:NOASSERTIONStargazers:2916Issues:66Issues:212

offensive_macos

Tracking of offensive macOS tooling, blogs, and related helpful information

bifrost

Objective-C library and console to interact with Heimdal APIs for macOS Kerberos

Language:Objective-CLicense:BSD-3-ClauseStargazers:122Issues:8Issues:1

Orchard

JavaScript for Automation (JXA) tool to do Active Directory enumeration.

Language:JavaScriptLicense:BSD-3-ClauseStargazers:93Issues:3Issues:1

LockSmith

ObjectiveC CLI tool for interacting with macOS Keychain

Language:Objective-CLicense:BSD-3-ClauseStargazers:69Issues:6Issues:1

HealthInspector

JXA situational awareness helper by simply reading specific files on a filesystem

Language:JavaScriptLicense:BSD-3-ClauseStargazers:60Issues:3Issues:1

macos_execute_from_memory

PoC of macho loading from memory

Language:MakefileStargazers:52Issues:6Issues:0

KeytabParser

Python script to parse Keytab files for macOS or *nix (typically /etc/krb5.keytab)

Language:PythonLicense:BSD-3-ClauseStargazers:34Issues:3Issues:0

dylibHijackScanner

Objective C dylibHijackScanner and analysis tool

Language:Objective-CLicense:BSD-3-ClauseStargazers:29Issues:3Issues:0
Language:Objective-CLicense:GPL-3.0Stargazers:15Issues:4Issues:0

macos-popups

Catalog Red Team techniques that cause popups in various macOS versions

macOSCameraCapture

Simple CLI utility to save off an image from every webcam hooked into a mac

Language:Objective-CLicense:GPL-3.0Stargazers:14Issues:2Issues:0

CursedChrome

Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies, allowing you to browse sites as your victims.

Language:JavaScriptStargazers:5Issues:1Issues:0

smbdoor

Windows kernel backdoor via registering a malicious SMB handler

Language:CLicense:Apache-2.0Stargazers:5Issues:2Issues:0

website

Personal blog on security

Language:JavaScriptLicense:MITStargazers:4Issues:3Issues:0

overview

Overview stats for its-a-feature repositories

Language:PythonLicense:NOASSERTIONStargazers:3Issues:2Issues:0

TCC-ClickJacking

A proof of concept for a clickjacking attack on macOS.

Language:SwiftStargazers:2Issues:1Issues:0

chronology

SpecterOps Historical Records

License:BSD-3-ClauseStargazers:1Issues:1Issues:0

electroniz3r

Take over macOS Electron apps' TCC permissions

Language:SwiftLicense:BSD-2-ClauseStargazers:1Issues:0Issues:0

JXA_Proc_Tree

A JXA script for enumerating running processes, printed out in a json, parent-child tree.

Language:JavaScriptStargazers:1Issues:1Issues:0

KnockKnock

Enumerate persistently installed software

Language:Objective-CLicense:GPL-3.0Stargazers:1Issues:1Issues:0

Mystikal

macOS Initial Access Payload Generator

Language:PythonLicense:BSD-3-ClauseStargazers:1Issues:1Issues:0

PoshC2

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Language:PowerShellLicense:BSD-3-ClauseStargazers:1Issues:1Issues:0

PrintTCCdb

JXA script for Mythic that prints the TCC.db

Language:JavaScriptStargazers:1Issues:1Issues:0

SwiftInMemoryLoading

Swift implementation of in-memory Mach-O loading on macOS

Language:CStargazers:1Issues:1Issues:0

cobalt_sync

Standalone Cobalt Strike operation logging Aggressor script for Ghostwriter 2.0+

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

CSOps

Utility to manipulate codesigned application in Mac OS X. Demonstrate the use of csops system call.

Language:Objective-CStargazers:0Issues:1Issues:0
Language:Objective-CStargazers:0Issues:1Issues:0

macos_shell_memory

Execute MachO binaries in memory using CGo

Language:CStargazers:0Issues:1Issues:0

tamatoa

If you have any questions, please open an issue.

License:UnlicenseStargazers:0Issues:0Issues:0