Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)
Dropped a new tool at DEF CON 32! Loot SCCM Distribution points via HTTP with
We've found credentials, certificates, custom apps, keystores, etc. What will you find?
đź”— https://github.com/badsectorlabs/sccm-http-looter
Dropped a new tool at DEF CON 32! Loot SCCM Distribution points via HTTP with
We've found credentials, certificates, custom apps, keystores, etc. What will you find?
đź”— https://github.com/badsectorlabs/sccm-http-looter
matteyeux/IDArling: Collaborative Reverse Engineering plugin for IDA Pro & Hex-Rays
https://github.com/matteyeux/IDArling/
https://github.com/matteyeux/IDArling/
GitHub
GitHub - matteyeux/IDArling: Collaborative Reverse Engineering plugin for IDA Pro & Hex-Rays
Collaborative Reverse Engineering plugin for IDA Pro & Hex-Rays - matteyeux/IDArling
captainzero93/security_harden_linux: Semi-automated bash scripts that provide security hardening for Linux, Debian based, 2024
https://github.com/captainzero93/security_harden_linux/
https://github.com/captainzero93/security_harden_linux/
GitHub
GitHub - captainzero93/security_harden_linux: Semi-automated security hardening for Linux / Debian / Ubuntu , 2025, attempts DISA…
Semi-automated security hardening for Linux / Debian / Ubuntu , 2025, attempts DISA STIG and CIS Compliance - captainzero93/security_harden_linux
Protect-Images-from-AI-PixelGuard:
PixelGuard protects images from AI scraping and unauthorized use in AI training, such as facial recognition models or style transfer algorithms. It employs multiple invisible protection techniques that mostly imperceptible to the eye but can interfere with AI processing.
https://github.com/captainzero93/Protect-Images-from-AI-PixelGuard
PixelGuard protects images from AI scraping and unauthorized use in AI training, such as facial recognition models or style transfer algorithms. It employs multiple invisible protection techniques that mostly imperceptible to the eye but can interfere with AI processing.
https://github.com/captainzero93/Protect-Images-from-AI-PixelGuard
GitHub
GitHub - captainzero93/Protect-Images-from-AI-PixelGuard: PixelGuard protects images from AI scraping and unauthorized use in AI…
PixelGuard protects images from AI scraping and unauthorized use in AI training, such as facial recognition models or style transfer algorithms. It employs multiple invisible protection techniques ...
Introduction to Windows Kernel Exploitation for Beginners
Part 1: https://mdanilor.github.io/posts/hevd-0/
Part 2: mdanilor.github.io/posts/hevd-1/
Part 3: mdanilor.github.io/posts/hevd-2/
Part 4: mdanilor.github.io/posts/hevd-3/
Part 5: mdanilor.github.io/posts/hevd-4/
Part 1: https://mdanilor.github.io/posts/hevd-0/
Part 2: mdanilor.github.io/posts/hevd-1/
Part 3: mdanilor.github.io/posts/hevd-2/
Part 4: mdanilor.github.io/posts/hevd-3/
Part 5: mdanilor.github.io/posts/hevd-4/
mdanilor.github.io
[Cracking Windows Kernel with HEVD] Chapter 0: Where do I start?
A beginers guide into a Windows kernel stack overflow vulnerability from zero to advanced bypasses.
windows-api-function-cheatsheets:
A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization, interprocess communication, Unicode string manipulation, error handling, Winsock networking operations, and registry operations.
https://github.com/7etsuo/windows-api-function-cheatsheets
A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization, interprocess communication, Unicode string manipulation, error handling, Winsock networking operations, and registry operations.
https://github.com/7etsuo/windows-api-function-cheatsheets
GitHub
GitHub - 7etsuo/windows-api-function-cheatsheets: A reference of Windows API function calls, including functions for file operations…
A reference of Windows API function calls, including functions for file operations, process management, memory management, thread management, dynamic-link library (DLL) management, synchronization,...
Dump #lsass using only #NTAPIS running 3 programs to create 3 JSON and 1 ZIP file... and generate the Minidump later!
https://github.com/ricardojoserf/TrickDump
https://github.com/ricardojoserf/TrickDump
GitHub
GitHub - ricardojoserf/TrickDump: Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump…
Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later! - ricardojoserf/TrickDump
#DriverJack: Turning #NTFS and Emulated Read-only Filesystems in an Infection and Persistence Vector
https://github.com/klezVirus/DriverJack
https://github.com/klezVirus/DriverJack
GitHub
GitHub - klezVirus/DriverJack: Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links…
Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths - klezVirus/DriverJack
Tools from the DEFCON 32 talk "SHIM me what you got - Manipulating Shim and Office for Code Injection"
Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.
Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.
https://github.com/deepinstinct/ShimMe
Office Injector - Invokes an RPC method in OfficeClickToRun service that will inject a DLL into a suspended process running as NT AUTHORITY\SYSTEM launched by the task scheduler service, thus achieving privilege escalation from administrator to SYSTEM.
Shim Injector - Writes an undocumented shim data structure into the memory of another process that causes apphelp.dll to apply the “Inject Dll” fix on the process without registering a new SDB file on the system, or even writing such file to disk.
https://github.com/deepinstinct/ShimMe
GitHub
GitHub - deepinstinct/ShimMe
Contribute to deepinstinct/ShimMe development by creating an account on GitHub.
#Dopamine is a semi-untethered #jailbreak for #iOS 15 and 16
https://github.com/opa334/Dopamine/releases/tag/2.2.2
https://github.com/opa334/Dopamine/releases/tag/2.2.2
GitHub
Release 2.2.2 · opa334/Dopamine
Stop redirecting all execve calls to posix_spawn, fixes issues with certain sandbox profiles (e.g. configd) that block posix_spawn but allow execve, fixes WPA2/3 ENTERPRISE networks not working (th...
#SCCMSecrets.py aims at exploiting #SCCM policies distribution for credentials harvesting, initial access and lateral movement.
https://github.com/synacktiv/SCCMSecrets
https://github.com/synacktiv/SCCMSecrets
GitHub
GitHub - synacktiv/SCCMSecrets: SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial…
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement. - synacktiv/SCCMSecrets
#tools
#Offensive_security
1. TrickDump dumps the lsass process without creating a Minidump file
https://github.com/ricardojoserf/TrickDump
2. traceeshark - Deep Linux runtime visibility meets Wireshark
https://github.com/aquasecurity/traceeshark
#Offensive_security
1. TrickDump dumps the lsass process without creating a Minidump file
https://github.com/ricardojoserf/TrickDump
2. traceeshark - Deep Linux runtime visibility meets Wireshark
https://github.com/aquasecurity/traceeshark
#tools
#Offensive_security
1. SCCM HTTP Looter
https://github.com/badsectorlabs/sccm-http-looter
2. Stealthy Bash Tool
https://github.com/hackerschoice/hackshell
3. Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
https://github.com/klezVirus/DriverJack
#Offensive_security
1. SCCM HTTP Looter
https://github.com/badsectorlabs/sccm-http-looter
2. Stealthy Bash Tool
https://github.com/hackerschoice/hackshell
3. Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths
https://github.com/klezVirus/DriverJack
#tools
#Cloud_Security
Grimoire - Generate datasets of cloud audit logs for common attacks
https://github.com/dataDog/grimoire
#Cloud_Security
Grimoire - Generate datasets of cloud audit logs for common attacks
https://github.com/dataDog/grimoire
#Cyber_Education
Using SeTcbPrivilege for educational purposes
https://github.com/daem0nc0re/PrivFu/tree/main/PowerOfTcb
Using SeTcbPrivilege for educational purposes
https://github.com/daem0nc0re/PrivFu/tree/main/PowerOfTcb
#tools
#cryptography
Project Wycheproof tests crypto libraries against known attacks
https://github.com/C2SP/wycheproof
#cryptography
Project Wycheproof tests crypto libraries against known attacks
https://github.com/C2SP/wycheproof
Draytek_Defcon.pdf
9.2 MB
#tools
#reversing
"Taking off the blindfold:
Detecting persistent threats on Draytek edge devices", 2024.
]-> Reverse Engineering and Observability toolkit for Draytek firewalls:
https://github.com/infobyte/draytek-arsenal
#reversing
"Taking off the blindfold:
Detecting persistent threats on Draytek edge devices", 2024.
]-> Reverse Engineering and Observability toolkit for Draytek firewalls:
https://github.com/infobyte/draytek-arsenal
Phishing. Examples of letters and analysis of attacks.
• This repository contains examples of phishing emails that were sent by APT groups to various companies around the world. In addition to examples, the repo includes presentations with analysis and description of phishing attacks. In general, the material is very interesting, especially if you do research and study various schemes:
➡ https://github.com/wddadk/Phishing-campaigns
• This repository contains examples of phishing emails that were sent by APT groups to various companies around the world. In addition to examples, the repo includes presentations with analysis and description of phishing attacks. In general, the material is very interesting, especially if you do research and study various schemes:
➡ https://github.com/wddadk/Phishing-campaigns
GitHub
GitHub - wddadk/Phishing-campaigns
Contribute to wddadk/Phishing-campaigns development by creating an account on GitHub.
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.
https://github.com/synacktiv/SCCMSecrets
https://github.com/synacktiv/SCCMSecrets
GitHub
GitHub - synacktiv/SCCMSecrets: SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial…
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement. - synacktiv/SCCMSecrets
TCP Reverse Shell C++
TCP reverse shell is a type of shell in which the attacker creates a connection from the target machine back to the attacker's machine, rather than the attacker connecting directly to the target. In this script, the attacker typically sets up a listener on a specified port on their own machine, and the victim machine is then compromised with malware that establishes a connection to the attacker's listener. Once the connection is established, the attacker has access to a command prompt on the victim machine, and can execute commands and interact with the system as if they were sitting at the machine itself. This technique is commonly used in cyber attacks and penetration testing
https://github.com/Untouchable17/Reverse-TCP-Shell‌‌
TCP reverse shell is a type of shell in which the attacker creates a connection from the target machine back to the attacker's machine, rather than the attacker connecting directly to the target. In this script, the attacker typically sets up a listener on a specified port on their own machine, and the victim machine is then compromised with malware that establishes a connection to the attacker's listener. Once the connection is established, the attacker has access to a command prompt on the victim machine, and can execute commands and interact with the system as if they were sitting at the machine itself. This technique is commonly used in cyber attacks and penetration testing
https://github.com/Untouchable17/Reverse-TCP-Shell‌‌
❤1