v4nyl's repositories

Aggressor-scripts

Aggressor scripts I've made for Cobalt Strike

License:GPL-2.0Stargazers:0Issues:0Issues:0

AggressorCollection

Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors

Stargazers:0Issues:0Issues:0

Chameleon

Chameleon: A tool for evading Proxy categorisation

Stargazers:0Issues:0Issues:0

CobaltStrike-Toolset

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

License:GPL-3.0Stargazers:0Issues:0Issues:0

EasyNet

Simple packer for arbitrary data using only .NET API calls. Produces a unique signature with every usage. Standalone program and library. Algorithm: Data <-> GZip <-> AES-256 <-> Base64.

License:MITStargazers:0Issues:0Issues:0

EoPLoadDriver

Proof of concept for abusing SeLoadDriverPrivilege (Privilege Escalation in Windows)

Language:C++License:BSD-2-ClauseStargazers:0Issues:0Issues:0

EventCleaner

A tool mainly to erase specified records from Windows event logs, with additional functionalities.

Language:C++Stargazers:0Issues:0Issues:0

fireELF

fireELF - Fileless Linux Malware Framework

License:MITStargazers:0Issues:0Issues:0

gargoyle

A memory scanning evasion technique

Language:C++License:AGPL-3.0Stargazers:0Issues:0Issues:0

HideShell

A JSP backdoor that enables under Tomcat hiding arbitrary JSP files, in addition to their access logs.

Stargazers:0Issues:0Issues:0

Invoke-UserSimulator

Simulates common user behaviour on local and remote Windows hosts.

Stargazers:0Issues:0Issues:0
License:AGPL-3.0Stargazers:0Issues:0Issues:0

LeoSpecial-VEH-Hook

Vectored Exception Handling Hooking Class

License:GPL-3.0Stargazers:0Issues:0Issues:0

mod_ringbuilder

Apache Module Backdoor (PoC)

License:GPL-3.0Stargazers:0Issues:0Issues:0

NtdllUnpatcher

Example code for EDR bypassing

Stargazers:0Issues:0Issues:0

Protectors

🛡️ Obfuscator, Encryption, Junkcode, Anti-Debug, PE protection/modification

Language:C++Stargazers:0Issues:0Issues:0

psportfwd

a simple portforwarder in ps1 with embeded c# code

Stargazers:0Issues:0Issues:0

pylnker

This is a Python port of lnk-parse-1.0, a tool to parse Windows .lnk files.

Language:PythonLicense:GPL-2.0Stargazers:0Issues:0Issues:0

Quickrundown

Smart overlay for Cobalt Strike PS function

Stargazers:0Issues:0Issues:0

RDPInception

A proof of concept for the RDP Inception Attack

Stargazers:0Issues:0Issues:0

SessionGopher

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.

Stargazers:0Issues:0Issues:0

smbdoor

Windows kernel backdoor via registering a malicious SMB handler

License:Apache-2.0Stargazers:0Issues:0Issues:0

Social-Engineering-Payloads

Collection of social engineering payloads

License:GPL-3.0Stargazers:0Issues:0Issues:0

ssh-inject

A ptrace POC by hooking SSH to reveal provided passwords

Stargazers:0Issues:0Issues:0

SSHoRTy

A progressive, customizable armored SSH tunnel implant for Linux and MacOS systems

License:MITStargazers:0Issues:0Issues:0

subTee-gits-backups

subTee gists code backups

Stargazers:0Issues:0Issues:0

TCPRelayInjecter2

Tool for injecting a "TCP Relay" managed assembly into an unmanaged process

Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

WMI_Persistence

A repo to hold some scripts pertaining WMI (Windows implementation of WBEM) forensics

Stargazers:0Issues:0Issues:0

WMImplant

This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.

License:GPL-3.0Stargazers:0Issues:0Issues:0