Conor Richard's repositories

manual-syscall-detect

A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.

Language:C++License:MITStargazers:97Issues:6Issues:1

SysWhispers2

AV/EDR evasion via direct system calls.

Language:AssemblyLicense:Apache-2.0Stargazers:97Issues:2Issues:0

atomiccaldera

A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files.

Language:PythonLicense:GPL-3.0Stargazers:72Issues:10Issues:0

Useful-BloodHound-Queries

A collection of Neo4j/BloodHound queries to collect interesting information.

License:MITStargazers:45Issues:3Issues:0

SessionHound

A pair of scripts to import session and local group information that has been collected from alternate data sources into BloodHound's Neo4j database.

Language:PythonLicense:MITStargazers:19Issues:3Issues:0

compressedCredBandit

A variation CredBandit that uses compression to reduce the size of the data that must be trasnmitted.

SharpMailBOF

A BOF.NET program to split a file into smaller chunks and email it via a specified SMTP relay.

Language:C#Stargazers:14Issues:2Issues:0

shellcode-learning

Working repository to store shellcode I am using to learn.

Language:AssemblyStargazers:10Issues:2Issues:0

Python-Exploit-Snippets

A collection of Python code snippets to aid in the authoring of Python Based PoCs.

Language:PythonStargazers:6Issues:2Issues:0

xenoscr.github.io

Conor Richard's (@xenoscr) GitHub.io Blog content

Language:SCSSLicense:MITStargazers:2Issues:2Issues:0
Language:C++Stargazers:0Issues:1Issues:0

AlternativeShellcodeExec

Alternative Shellcode Execution Via Callbacks

Language:C++License:MITStargazers:0Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

Creality-Ender-3-Max-Marlin-Configuration

Marlin configuration files for the Creality Ender 3 Max with a BL-Touch.

Stargazers:0Issues:2Issues:0

DetectionLab-XenosCR

Automate the creation of a lab environment complete with security tooling and logging best practices

Language:HTMLLicense:MITStargazers:0Issues:1Issues:0
Language:CStargazers:0Issues:1Issues:0

experiments

Expriments

Language:PythonStargazers:0Issues:1Issues:0

lab-scripts

Some scripts I use to help speed up lab machine setups.

Language:ShellLicense:MITStargazers:0Issues:2Issues:0

loadlibrary

Porting Windows Dynamic Link Libraries to Linux

Language:CLicense:GPL-2.0Stargazers:0Issues:0Issues:0

LOLBAS-1

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Language:XSLTLicense:GPL-3.0Stargazers:0Issues:1Issues:0

LOLBAS-old

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Language:XSLTStargazers:0Issues:2Issues:0

NetUser

使用windows api添加用户,可用于net无法使用时.分为nim版,c++版本,RDI版,BOF版。

Language:C++Stargazers:0Issues:1Issues:0

Proxy-Function-Calls-For-ETwTI

The code is a pingback to the Dark Vortex blog: https://0xdarkvortex.dev/hiding-memory-allocations-from-mdatp-etwti-stack-tracing/

Language:CLicense:GPL-3.0Stargazers:0Issues:0Issues:0

qmk_firmware

Open-source keyboard firmware for Atmel AVR and Arm USB families

Language:CLicense:GPL-2.0Stargazers:0Issues:0Issues:0

SharpUnhooker

C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,and kernelbase.dll)

Language:C#Stargazers:0Issues:1Issues:0

shellcode-odzhan

Shellcodes for Windows/Linux/BSD running on x86, AMD64, ARM, ARM64

Language:CStargazers:0Issues:0Issues:0

threaded-bucket-finder

A python script to find S3 Buckets for penetration testing or other engagements.

Language:PythonStargazers:0Issues:1Issues:0

tri-a-gen

Trigen is a Python script which uses different combinations of Win32 function calls in generated VBA to execute shellcode.

Language:PythonStargazers:0Issues:1Issues:0

wowGrail

PoC: Rebuild A New Path Back to the Heaven's Gate (HITB 2021)

Language:C++License:GPL-3.0Stargazers:0Issues:1Issues:0

YubiKey-Guide

Guide to using YubiKey for GPG and SSH

Language:ShellLicense:MITStargazers:0Issues:0Issues:0