Plus récents

RustScan

RustScan is a tool that turns a 17 minutes Nmap scan into 19 seconds.

github.com/RustScan/RustScan

Dynamic Assembly Loader

DotNet Assembly Loader using a Dynamic Method & Emitted MSIL instructions

gist.github.com/sdcampbell/41d

asminject

Injects arbitrary assembly or precompiled binary payloads directly into x86-64, x86, and ARM32 Linux processes without the use of ptrace

github.com/BishopFox/asminject

Notre monde est devenu ... le théâtre de combats

sciencesetavenir.fr/high-tech/

« Le monde est un chaos, et son désordre excède tout ce qu'on y voudrait apporter de remède. » ( Pierre Corneille )

Seuls les ignorants seront surpris de la tournure des évènements. Alors peut-être devrions-nous s'interroger sur la fabrique de nos ignares ?

« La crainte de la guerre est encore pire que la guerre elle-même » ( Sénèque )

Certaines menaces sont belles et bien nouvelles cependant combien d'entre elles le sont et combien étaient-elles prévisibles ?

Everybody has a plan until they get punched in the mouth ( Mike Tyson )

Doit-on s'interroger sur le temps restant avant ouverture de cette maudite boîte de Pandore ou devrions-nous accepter son ouverture et œuvrer sans tarder à bâtir nos forces avec une volonté de vaincre ?

« Un changement en prépare un autre. » ( Nicolas Machiavel )

몾 Artemis a partagé

#AADInternals @bsidesorlando edition is out now!

New functionality:
▪ Get access tokens for managed identities
▪ Add new MOERA domains (.onmicrosoft.com)

And as demonstrated in my BSides Orlando talk:
▪ Modify #AzureAD policy details (including Conditional Access metadata) without detailed Audit Log events

Change log: aadinternals.com/aadinternals/

Havoc v0.4.1

Havoc is a modern and malleable post-exploitation command and control framework

  • Socks4a proxy support

github.com/HavocFramework/Havo

ntfsDump

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures

💭 Used successfully for reading ntds.dit on a DC

github.com/3gstudent/ntfsDump

Pyramid

The main purpose of the tool is to perform offensive tasks by leveraging some Python evasion properties and looking as a legit Python application usage.

github.com/naksyn/Pyramid

RunasCs

Added flag --bypass-uac that allows to spawn a process as an Administrator (if password is known) with full privileges

github.com/antonioCoco/RunasCs

PIVert-Relay

Modified Ceri's PIVert to support authentication where the smart card holding the private key is on another machine

cube0x0.github.io/Relaying-Yub

NimicStack

Pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs.

github.com/frkngksl/NimicStack

VulnerabilitiesDataImport is a standalone script that adds information about unpatched vulnerabilities to BloodHound based on parsed vulnerability scanners reports.

github.com/zeronetworks/BloodH

Plus anciens
nanao

Comme le soleil, les machines ne se couchent jamais.