Outflank B.V. (@outflanknl)

Top repositories

1

RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
Python
2,238
star
2

EvilClippy

A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
C#
2,017
star
3

Dumpert

LSASS memory dumper using direct system calls and API unhooking.
C
1,376
star
4

C2-Tool-Collection

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
C
1,029
star
5

Invoke-ADLabDeployer

Automated deployment of Windows and Active Directory test lab networks. Useful for red and blue teams.
PowerShell
473
star
6

SharpHide

Tool to create hidden registry keys.
C#
451
star
7

Spray-AD

A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.
C++
409
star
8

PrintNightmare

C
329
star
9

Ps-Tools

Ps-Tools, an advanced process monitoring toolkit for offensive operations
C
326
star
10

Excel4-DCOM

PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)
PowerShell
321
star
11

Recon-AD

Recon-AD, an AD recon tool based on ADSI and reflective DLLโ€™s
C++
294
star
12

InlineWhispers

Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)
Assembly
293
star
13

Scripts

Small scripts that make life better
JavaScript
284
star
14

FindObjects-BOF

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.
267
star
15

WdToggle

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.
216
star
16

TamperETW

PoC to demonstrate how CLR ETW events can be tampered.
C
187
star
17

Zipper

Zipper, a CobaltStrike file and folder compression utility.
C
186
star
18

HelpColor

Agressor script that lists available Cobalt Strike beacon commands and colors them based on their type
183
star
19

NetshHelperBeacon

Example DLL to load from Windows NetShell
C++
169
star
20

Presentations

Presentation material presented by Outflank team members at public events.
165
star
21

Net-GPPPassword

.NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.
C#
159
star
22

external_c2

POC for Cobalt Strike external C2
C
113
star
23

DoH_c2_Trigger

Code for blogpost: https://outflank.nl/blog/2018/10/25/building-resilient-c2-infrastructues-using-dns-over-https/
PowerShell
52
star
24

Training-MSOfficeOffensiveTradecraft

Info related to the Outflank training: Microsoft Office Offensive Tradecraft
42
star
25

PasswordDump2ELK

Clean public password dump files and store in ELK
Shell
37
star
26

unmanaged-dotnet-patch

Modify managed functions from unmanaged code
C++
34
star
27

RedELK-workshop

Items related to the RedELK workshop given at security conferences
23
star
28

Exploits

Exploits developped by Outflank B.V. team members
Python
20
star
29

RedFile

Serving files with conditions, serverside keying and more.
Python
19
star
30

Invoke-Templator

A PowerShell script to parse the docx/docm file format and update the template location.
PowerShell
17
star