WMI_Backdoor
A PoC WMI backdoor presented at Black Hat 2015
There are no reviews yet. Be the first to send feedback to the community and the maintainers!
PowerShellArsenal
A PowerShell Module Dedicated to Reverse EngineeringCimSweep
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.PIC_Bindshell
Position Independent Windows Shellcode Written in CPSSysmonTools
Sysmon Tools for PowerShellPSReflect
Easily define in-memory enums, structs, and Win32 functions in PowerShellWDACTools
A PowerShell module to facilitate building, configuring, deploying, and auditing Windows Defender Application Control (WDAC) policiesWinPETools
A module designed to simplify the creation, customization, and deployment of bootable Windows Preinstallation Environment (WinPE) images.BHUSA2018_Sysmon
All materials from our Black Hat 2018 "Subverting Sysmon" talkAntimalwareBlight
Execute PowerShell code at the antimalware-light protection level.DeviceGuardBypassMitigationRules
A reference Device Guard code integrity policy consisting of FilePublisher deny rules for published Device Guard configuration bypassesPoCSubjectInterfacePackage
A proof-of-concept subject interface package (SIP) used to demonstrate digital signature subversion attacks.BCD
BCD is a module to interact with boot configuration data (BCD) either locally or remotely using the ROOT/WMI:Bcd* WMI classes. The functionality of the functions in this module mirror that of bcdedit.exe.WDACPolicies
A collection of Windows software baseline notes with corresponding Windows Defender Application Control (WDAC) policiesTCGLogTools
A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In order to retrieve these logs, you must be running at least Windows 8 with the TPM enabled.WindowsEventLogMetadata
Event metadata collected across all manifest-based ETW providers on Window 10 1903ShellcodeExec
A simple shellcode runnerCatalogTools
A PowerShell module to assist in parsing and managing catalog files.UnicornPowerShell
A PowerShell binding for the Unicorn EngineMSFTTraceMessageFormat
All TMF files that I extracted from Microsoft PDBs.mattifestation
Love Open Source and this site? Check out how you can help us