30 open-source projects similar to sensepost/ruler, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Ruler alternative.
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
Store and execute an encrypted windows binary from inside memory, without a single bit touching disk.
Donut is a toolset for loading and executing payloads in memory, featuring a position-independent shellcode generator, an in-memory payload injector, and a .NET assembly loader. It is designed to convert executable files and scripts into shellcode that can be executed within the memory space of a remote process without writing files to disk. The project specializes in security evasion through memory-based patching and payload obfuscation using symmetric block ciphers and compression. It includes a remote payload stager to retrieve encrypted modules from HTTP or DNS servers during runtime, red
A Proof of Concept for weaponizing SysWhispers for making direct system calls in Cobalt Strike Beacon Object File.
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)
`` ██╗ ██╗ ██╗███╗ ██╗ ██████╗███████╗███╗ ███╗ █████╗ ███████╗██╗ ██╗ ██║ ╚██╗ ██╔╝████╗ ██║██╔════╝██╔════╝████╗ ████║██╔══██╗██╔════╝██║ ██║ ██║ ╚████╔╝ ██╔██╗ ██║██║ ███████╗██╔████╔██║███████║███████╗███████║ ██║ ╚██╔╝ ██║╚██╗██║██║ ╚════██║██║╚██╔╝██║██╔══██║╚════██║██╔══██║ ███████╗██║…
To view the latest version of Freeze or to submit an issue, reference https://github.com/Tylous/Freeze.
To view the latest version of ScareCrow or to submit an issue, reference https://github.com/Tylous/ScareCrow.
RuralBishop is practically a carbon copy of UrbanBishop by b33f, but all P/Invoke calls have been replaced with D/Invoke.
script to retrieve information via O365 and AzureAD with a valid cred
:triangularflagon_post: This is the public repository of Inceptor, for latest version and updates please consider supporting us through https://porchetta.industries/
Shellcode runner framework for application whitelisting bypasses and DLL side-loading. The shellcode included in this project spawns calc.exe.
VBA purge your Office documents with OfficePurge. VBA purging removes P-code from module streams within Office documents. Documents that only contain source code and no compiled code are more likely to evade AV detection and YARA rules. Read more here .
Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code. To do this Dendrobate uses EasyHook and packs the injected component, Dendron, using Fody & Costura . This is all done automatically so all you need to do when you compile…
SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA scripts. The current gadget triggers a call to Activator.CreateInstance() when deserialized using BinaryFormatter from jscript/vbscript/vba, this…
generate CobaltStrike's cross-platform payload
To view the latest version of Ivy or to submit an issue, reference https://github.com/Tylous/Ivy.
Proof-of-concept obfuscation toolkit for C# post-exploitation tools. This will perform the below actions for a C# visual studio project.
Shhhloader is a work in progress shellcode loader. It takes raw shellcode as input and compiles a C++ stub that does a bunch of different things to try and bypass AV/EDR. The included python builder will work on any Linux system that has Mingw-w64 installed.
Weaponize DLL hijacking easily. Backdoor any function in any DLL without disrupting normal process operation.
This project is a post-exploitation framework and command and control platform designed for security research and penetration testing. It functions as a remote access tool consisting of a central command server and encrypted executable payloads that establish reverse shell connections. The system utilizes a web-based dashboard for multi-client administration, allowing for remote host monitoring and direct shell access through an in-browser terminal. It generates cross-platform, encrypted binaries that employ a multi-stage delivery chain and a key exchange mechanism to secure communications.