Mariusz Banach (@mgeeky)
  • Stars
    star
    11,478
  • Global Rank 1,739 (Top 0.07 %)
  • Followers 2,266
  • Following 94
  • Registered about 13 years ago
  • Most used languages
    Python
    33.3 %
    C++
    25.0 %
    PowerShell
    11.1 %
    C
    8.3 %
    C#
    5.6 %
    Shell
    2.8 %
    VBA
    2.8 %
    VBScript
    2.8 %
    MATLAB
    2.8 %
    Batchfile
    2.8 %
    PHP
    2.8 %
  • Location πŸ‡΅πŸ‡± Poland
  • Country Total Rank 21
  • Country Ranking
    VBA
    1
    VBScript
    1
    C++
    4
    Batchfile
    6
    Python
    7
    C#
    20
    C
    35
    MATLAB
    115
    Shell
    141
    PHP
    150

Top repositories

1

Penetration-Testing-Tools

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
PowerShell
2,361
star
2

cobalt-arsenal

My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+
PowerShell
940
star
3

ThreadStackSpoofer

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners and analysts.
C++
919
star
4

RedWarden

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation
Python
842
star
5

ShellcodeFluctuation

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents
C++
818
star
6

ProtectMyTooling

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable.
PowerShell
772
star
7

PackMyPayload

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats. Supports: ZIP, 7zip, PDF, ISO, IMG, CAB, VHD, VHDX
Python
772
star
8

decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam
Python
485
star
9

Stracciatella

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup
C#
479
star
10

tomcatWarDeployer

Apache Tomcat auto WAR deployment & pwning penetration testing tool.
Python
393
star
11

ElusiveMice

Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
C
378
star
12

UnhookMe

UnhookMe is an universal Windows API resolver & unhooker addressing problem of invoking unmonitored system calls from within of your Red Teams malware
C++
337
star
13

SharpWebServer

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality
C#
271
star
14

AzureRT

AzureRT - A Powershell module implementing various Azure Red Team tactics
PowerShell
217
star
15

expdevBadChars

Bad Characters highlighter for exploit development purposes supporting multiple input formats while comparing.
Python
200
star
16

msidump

MSI Dump - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner.
Python
178
star
17

RobustPentestMacro

This is a rich-featured Visual Basic macro code for use during Penetration Testing assignments, implementing various advanced post-exploitation techniques.
VBScript
138
star
18

Exploit-Development-Tools

A bunch of my exploit development helper tools, collected in one place.
Python
137
star
19

VisualBasicObfuscator

Visual Basic Code universal Obfuscator intended to be used during penetration testing assignments.
Python
129
star
20

msi-shenanigans

Proof of Concept code and samples presenting emerging threat of MSI installer files.
Python
73
star
21

PE-library

Lightweight Portable Executable parsing library and a demo peParser application.
C++
70
star
22

HEVD_Kernel_Exploit

Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.
C++
58
star
23

procmon-filters

SysInternals' Process Monitor filters repository - collected from various places and made up by myself. To be used for quick Behavioral analysis of testing specimens. Inspired and based on Lenny Zeltser's collection.
56
star
24

PhishingPost

PHP Script intdended to be used during Phishing campaigns as a credentials collector linked to backdoored HTML <form> action parameter
PHP
53
star
25

burpContextAwareFuzzer

BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JSON; XML; GWT; binary) and following encoding-scheme applied originally.
Python
39
star
26

CustomXMLPart

A PoC weaponising CustomXMLPart for hiding malware code inside of Office document structures.
VBA
32
star
27

dirbuster

wfuzz, SecLists and john -based dirbusting / forceful browsing script intended to be used during web pentest assingments
Shell
32
star
28

ntfs-journal-viewer

Utterly simple NTFS Journal dumping utility. Handy when it comes to Computer Forensics and Malware Forensics Ops.
C
30
star
29

LISET

Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident response (either forensic or malware oriented).
Batchfile
25
star
30

digitalocean-app-redirector

Reverse-HTTP Redirector via DigitalOcean Apps Platform
Python
24
star
31

prc_xchk

User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.
C++
17
star
32

RPISEC-MBE-Solutions

Solutions to the RPISEC MBE / Modern Binary Exploitation VM & course.
Python
17
star
33

PEInfo

Another Portable Executable files analysing stuff
C++
17
star
34

mgeeky

8
star
35

stegano1

College project implementing some of the compression and image steganographic algorithms.
C++
4
star
36

DISASM

Simple disassembling library (currently only x86)
C++
3
star
37

linux-utils

Some linux utils I've coded and decided to share.
C
2
star
38

Symulacja-Reaktora-Jadrowego

(Polish only) Program przygotowywany na uczelnie w ramach kursu "Symulacje Komputerowe". Przedstawia hipotetyczna prace reaktora jadrowego w roznych stanach i konfiguracjach.
MATLAB
1
star