Lists (19)
Sort Name ascending (A-Z)
Stars
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquir…
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy lea…
Educational, CTF-styled labs for individuals interested in Memory Forensics
蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。
An advanced memory forensics framework
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing
Attack and defend active directory using modern post exploitation adversary tradecraft activity
StandIn is a small .NET35/45 AD post-exploitation toolkit
RunasCs - Csharp and open version of windows builtin runas.exe
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…
ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound, and also supports full-object dumping to NDJSON.
This repo contains some Amsi Bypass methods i found on different Blog Posts.
PowerShell Obfuscator. A PowerShell script anti-virus evasion tool
Extract credentials from lsass remotely
A swiss army knife for pentesting networks
lgandx / Responder
Forked from SpiderLabs/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…