Github tools
2.73K subscribers
33 photos
2 videos
58 files
361 links
Github useful scripts and tools
Download Telegram
Welcome to this new #workshop focused on the #Windows DLL Loading internals.

https://github.com/OtterHacker/Conferences/tree/main/Defcon32
C2 Cloud - The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised backdoors, just like accessing an EC2 instance in the AWS cloud. It can manage several simultaneous backdoor sessions with a user-friendly interface.

https://github.com/govindasamyarun/c2-cloud?tab=readme-ov-file#application-setup
UnpromptedControl

Unprompted Control is a utility that allows you to automatically remove objects from images and repair corrupted images using deep learning and blending techniques.

The Control Net Model and Stable Diffusion Inpaint Pipeline play a key role in this process, guiding the restoration and ensuring that the results blend naturally with the surrounding image content.

However, this method has limitations, especially when processing images of people's faces and bodies, and may require masking not only the subject but also its shadows to achieve optimal results.

Despite these challenges, the repository provides a valuable tool for seamless object recovery and deletion.

https://github.com/vijishmadhavan/UnpromptedControl
1👍1
Manipulating Shim and Office for Code Injection

Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.

Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.

DefCon Presentation

https://github.com/deepinstinct/ShimMe
👍1
Search by image

Browser extension for Chrome, Edge and Safari.

Allows to take a screenshot of part of your screen and search for it in 45 different reverse image search engines.

Also search for an image via a link or downloaded from computer.

https://github.com/dessant/search-by-image
1
SurfSense

SurfSense is a tool that helps users remember and organize content saved while browsing the Internet.

It works as a personal knowledge graph, allowing you to save, search, and interact with your web browser history using natural language queries.

The platform supports self-hosting, integrates with Neo4j for database management, and uses OpenAI's GPT models to improve search.

To get started with SurfSense, users must set up the backend, install the necessary dependencies, and run the Chrome extension, which captures and saves web content directly from the browser.

The extension allows you to save snapshots of web pages and later request the saved content.

https://github.com/MODSetter/SurfSense
💔1
Archive of APT phishing campaigns

This repository contains papers on APT groups, which include examples of emails used in the phishing campaigns. Often, papers on APT group attacks do not provide email examples, which prompted me to create a repository that specifically includes on papers containing phishing emails. This list will be gradually expanded. Contributions are welcome. For reliability, each link has been duplicated through web archive.

https://github.com/wddadk/Phishing-campaigns
Virtual machine focused on research in the field of OSINT. It has rich functionality and many up-to-date tools. In addition to the software, you will find a rich set of various cheat sheets, browser extensions (Mozilla and GH) and other necessary resources that will help you in your investigation.

https://github.com/midnit3Z0mbi3/Kali-Linux-OSINT-VM
1
IoT_cwe.pdf
420.3 KB
#IoT_Security
"Towards Weaknesses and Attack Patterns Prediction for IoT Devices", 2024.
]-> IoT CWE/CAPEC Datasets:
https://github.com/criveraalvarez/IoT_CWE-CAPEC_Dataset
Deep-HLR - the script retrieves social network accounts subscribed to the number (Amazon, Badoo, Bumble, Microsoft, Skype, Telegram, Twitter, Uber, Xiaomi, Bukalapak, Google Duo, Kakaotalk, TikTok, Google Account, Linkedin, Battlenet, Instagram, CallerID, Yandex, VK, Economic Times, WhatsApp, Line, NextDoor, Remind, Flipkart, JD, Viber and Venmo), checks availability, connectivity, portability and assesses risk, extracts operator, checks if it is included in data leaks, Retrieves geographic location and device information associated with a phone number in json format. It uses the Defastra Deep Phone HLR Check API to work.

➡️https://github.com/e-m3din4/deep-hlr
🔥2👍1