Mez0 (mez-0)

mez-0

Geek Repo

Company:@TrustedSec

Location:United Kingdom

Home Page:mez0.cc

Twitter:@__mez0__

Github PK Tool:Github PK Tool


Organizations
preemptdev

Mez0's starred repositories

tabulate

Table Maker for Modern C++

Language:C++License:MITStargazers:1858Issues:0Issues:0
Stargazers:24Issues:0Issues:0

Masky

Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory

Language:PythonLicense:MITStargazers:373Issues:0Issues:0

capemon

capemon: CAPE's monitor

Language:CLicense:GPL-3.0Stargazers:90Issues:0Issues:0

DetectWindowsCopyOnWriteForAPI

Enumerate various traits from Windows processes as an aid to threat hunting

Language:C++License:AGPL-3.0Stargazers:178Issues:0Issues:0

TeamFiltration

TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts

Language:C#License:GPL-3.0Stargazers:1012Issues:0Issues:0

blackhat-usa-2022-demos

Demos for the Blackhat USA 2022 talk "Taking Kerberos to the Next Level"

Language:PowerShellLicense:GPL-3.0Stargazers:257Issues:0Issues:0

cs-token-vault

In-memory token vault BOF for Cobalt Strike

Language:CLicense:MITStargazers:135Issues:0Issues:0

AceLdr

Cobalt Strike UDRL for memory scanner evasion.

Language:CLicense:MITStargazers:858Issues:0Issues:0
Language:C++License:MITStargazers:444Issues:0Issues:0
Language:C++License:MITStargazers:97Issues:0Issues:0

protections-artifacts

Elastic Security detection content for Endpoint

Language:YARALicense:NOASSERTIONStargazers:957Issues:0Issues:0

NimicStack

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs

Language:NimStargazers:88Issues:0Issues:0

CrossLinked

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

Language:PythonLicense:GPL-3.0Stargazers:1212Issues:0Issues:0

DeathSleep

A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.

Language:PythonStargazers:491Issues:0Issues:0

ProtectMyTooling

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.

Language:PowerShellLicense:MITStargazers:821Issues:0Issues:0

CoffeeLdr

Beacon Object File Loader

Language:CStargazers:270Issues:0Issues:0

Azure-Red-Team

Azure Security Resources and Notes

Language:PowerShellStargazers:1433Issues:0Issues:0

VX-API

Collection of various malicious functionality to aid in malware development

Language:C++License:MITStargazers:1371Issues:0Issues:0

windows-coerced-authentication-methods

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.

Language:PythonStargazers:476Issues:0Issues:0

maldev-for-dummies

A workshop about Malware Development

Language:NimLicense:NOASSERTIONStargazers:1484Issues:0Issues:0

CallStackSpoofer

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

Language:C++Stargazers:399Issues:0Issues:0

MalSeclogon

A little tool to play with the Seclogon service

Language:CLicense:GPL-3.0Stargazers:300Issues:0Issues:0

Mangle

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs

Language:GoLicense:MITStargazers:1150Issues:0Issues:0

Brute-Ratel-C4-Community-Kit

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

Language:CLicense:GPL-3.0Stargazers:253Issues:0Issues:0

viddy

👀 A modern watch command. Time machine and pager etc.

Language:GoLicense:MITStargazers:4535Issues:0Issues:0
Language:PythonStargazers:706Issues:0Issues:0

Ekko

Sleep Obfuscation

Language:CStargazers:643Issues:0Issues:0

sheepl

Sheepl : Creating realistic user behaviour for supporting tradecraft development within lab environments

Language:PythonLicense:MITStargazers:393Issues:0Issues:0