Crypt0-M3lon/wmi-rs
WMI crate for rust
WMI crate for rust
Basically a KrabsETW rip-off written in Rust
Six Degrees of Domain Admin
A Fast (and safe) parser for the Windows XML Event Log (EVTX) format
A repository for using windows event forwarding for incident detection and response
Transform Linux Audit logs for SIEM usage
Small and highly portable detection tests based on MITRE's ATT&CK.
Collection of shellcode injection techniques packed in a D/Invoke weaponized DLL
A JSON schema based file editor for Windows.
⛴ Docker image of Nextcloud
☁️ Nextcloud server, a safe home for all your data
This is used for contributions to the Windows 10 content for IT professionals on docs.microsoft.com.
Covenant is a collaborative .NET C2 framework for red teamers.
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
The BloodHound C# Ingestor
Windows Exploit Suggester - Next Generation
PowerSploit - A PowerShell Post-Exploitation Framework
Python script for analyis of the "Trust.csv" file generated by Veil PowerView. Provides graph based analysis and output.
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
SharpUp is a C# port of various PowerUp functionality.
A little tool to play with Windows security
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
Automatic SQL injection and database takeover tool
Metasploit Framework
WebVirtCloud is virtualization web interface for admins and users