There are no reviews yet. Be the first to send feedback to the community and the maintainers!
PowerShellArsenal
A PowerShell Module Dedicated to Reverse EngineeringCimSweep
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.PIC_Bindshell
Position Independent Windows Shellcode Written in CWMI_Backdoor
A PoC WMI backdoor presented at Black Hat 2015PSSysmonTools
Sysmon Tools for PowerShellPSReflect
Easily define in-memory enums, structs, and Win32 functions in PowerShellWDACTools
A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policiesWinPETools
A module designed to simplify the creation, customization, and deployment of bootable Windows Preinstallation Environment (WinPE) images.BHUSA2018_Sysmon
All materials from our Black Hat 2018 "Subverting Sysmon" talkAntimalwareBlight
Execute PowerShell code at the antimalware-light protection level.DeviceGuardBypassMitigationRules
A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypassesPoCSubjectInterfacePackage
A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.BCD
BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functionality of the functions in this module mirror that of bcdedit.exe.WDACPolicies
A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policiesWindowsEventLogMetadata
Event metadata collected across all manifest-based ETW providers on Window 10 1903ShellcodeExec
A simple shellcode runnerCatalogTools
A PowerShell module to assist in parsing and managing catalog files.UnicornPowerShell
A PowerShell binding for the Unicorn EngineMSFTTraceMessageFormat
All TMF files that I extracted from Microsoft PDBs.mattifestation
Love Open Source and this site? Check out how you can help us