w0rk3r's Windows Hacking Library
Відкрити в Telegram
Manual job, I'm not a bot ;) @BlueTeamLibrary @W0rk3r
Показати більшеКраїна не вказанаТехнології та додатки42 664
1 663
Підписники
Немає даних24 години
Немає даних7 днів
Немає даних30 днів
Архів дописів
5 Ways to Find Systems Running Domain Admin Processes
https://blog.netspi.com/5-ways-to-find-systems-running-domain-admin-processes/
@WindowsHackingLibrary
DomainPasswordSpray
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain.
https://github.com/dafthack/DomainPasswordSpray
@WindowsHackingLibrary
MailSniper
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
https://github.com/dafthack/MailSniper
@WindowsHackingLibrary
Enumerating remote access policies through GPO
https://labs.mwrinfosecurity.com/blog/enumerating-remote-access-policies-through-gpo/
@WindowsHackingLibrary
A new look at null sessions and user enumeration
https://sensepost.com/blog/2018/a-new-look-at-null-sessions-and-user-enumeration/
@WindowsHackingLibrary
DLL Hijacking via URL files
https://insert-script.blogspot.com.br/2018/05/dll-hijacking-via-url-files.html
@WindowsHackingLibrary
Windows Userland Persistence Fundamentals
http://www.fuzzysecurity.com/tutorials/19.html
@WindowsHackingLibrary
Not a Security Boundary: Bypassing User Account Control
Matt Nelson at Derbycon 2017
Microsoft's User Account Control feature, introduced in Windows Vista, has been a topic of interest to many in the security community. Since UAC was designed to force user approval for administrative actions, attackers (and red teamers) encounter UAC on nearly every engagement. As a result, bypassing this control is a task that an actor often has to overcome, despite its lack of formal designation as a security boundary. This talk highlights what UAC is, previous work by others, research methodology, and details several technical UAC bypasses developed by the author.
https://youtu.be/c8LgqtATAnE
@SecTalks
Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts
https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts
@windowshackinglibrary
Kerberos Party Tricks: Weaponizing Kerberos Protocol Flaws
http://www.exumbraops.com/blog/2016/6/1/kerberos-party-tricks-weaponizing-kerberos-protocol-flaws
@windowshackinglibrary
Ring +3 Malwares: Few tricks
http://www.blackstormsecurity.com/docs/BSIDES_2018_RELEASE.pdf
@windowshackinglibrary
Blue Cloud of Death: Red Teaming Azure
https://speakerdeck.com/tweekfawkes/blue-cloud-of-death-red-teaming-azure-1
@windowshackinglibrary
Domain user Enumeration Tool
https://github.com/sensepost/UserEnum/blob/master/README.md
@windowshackinglibrary
Detecting hypervisor presence on windows 10
https://revers.engineering/detecting-hypervisor-presence-on-windows-10/
@windowshackinglibrary
Gathering AD Data with the Active Directory PowerShell Module
https://adsecurity.org/?p=3719
Unofficial Guide to Mimikatz & Command Reference
https://adsecurity.org/?page_id=1821
Hiding Metasploit Shellcode to Evade Windows Defender
https://blog.rapid7.com/2018/05/03/hiding-metasploit-shellcode-to-evade-windows-defender/
WMIC.EXE Whitelisting Bypass - Hacking with Style, Stylesheets
https://subt0x11.blogspot.com.br/2018/04/wmicexe-whitelisting-bypass-hacking.html
Exchange-AD-Privesc. Repository of Exchange privilege escalations to Active Directory
This repository provides a few techniques and scripts regarding the impact of Microsoft Exchange deployment on Active Directory security.
https://github.com/gdedrouas/Exchange-AD-Privesc
Skip Cracking Responder Hashes and Relay Them
http://threat.tevora.com/quick-tip-skip-cracking-responder-hashes-and-replay-them
