
pict
Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Recover the default privilege set of a LOCAL/NETWORK SERVICE account

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Extract credentials from lsass remotely

Win32 and Kernel abusing techniques for pentesters

A fully functional DanderSpritz lab in 2 commands



A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

exp for CVE-2019-0887