- Application Whitelisting Bypass with WMIC and XSL
- Forcing iexplore.exe to Load a Malicious DLL via COM Abuse
- PowerShell Constrained Language Mode Bypass
- PowerShell without PowerShell
- README
- T1117 - Regsvr32 aka Squiblydoo
- T1118 - InstallUtil
- T1170 - MSHTA Code Execution
- T1191 - CMSTP Code Execution
- T1196 - Control Panel Item Code Execution
- T1202 - Forfiles Indirect Command Execution
- T1216 - Signed Script CE
- Using MSBuild to Execute Shellcode in C#
- APC Queue Code Injection
- Backdooring a PE Executable with Shellcode
- Backdooring Portable Executables (PE) with Shellcode
- DLL Injection
- Early Bird APC Queue Code Injection
- Executing Shellcode with Inline Assembly in C/C++
- Finding Kernel32 Base and Function Addresses in Shellcode
- How to Hook Windows API using C++
- Loading and Executing Shellcode from Portable Executable Resources
- Process Doppelganging
- Process Hollowing and PE Image Relocations
- Process Injection
- README
- Reflective DLL Injection
- Reflective Shellcode DLL Injection
- SetWindowHookEx Code Injection
- Shellcode Execution in a Local Process with QueueUserAPC and NtTestAlert
- Dump Credentials from LSASS Process using Mimikatz
- Dumping and Cracking MSCash Cached Domain Credentials
- Dumping Credentials from lsass.exe Process Memory
- Dumping Domain Controller Hashes via WMIC and Shadow Copy using vssadmin
- Dumping LSA Secrets
- Dumping LSASS Passwords without Mimikatz (MiniDumpWriteDump AV Signature Bypass)
- Forcing WDigest to Store Credentials in Plaintext
- Network vs Interactive Logons
- ntds.dit Enumeration
- Reading DPAPI Encrypted Secrets with Mimikatz and C++
- README
- SAM
- T1174 - Password Filter DLL
- T1214 - Credentials in Registry
- AV Bypass with Metasploit Templates
- Bypassing Cylance and other AVs/EDRs by Unhooking Windows APIs
- Bypassing IDS Signatures with Simple Reverse Shells
- Bypassing Windows Defender: One TCP Socket Away from Meterpreter and Cobalt Strike Beacon
- Command-line Obfuscation
- Downloading File with certutil
- Evading Windows Defender using Classic C Shellcode Launcher with 1-byte change
- Executing CSharp Assemblies from JScript and WScript with DotNetToJScript
- File Smuggling with HTML and JavaScript
- Masquerading Processes in Userland through _PEB
- README
- T1027 - Obfuscated PowerShell Invocations
- T1045 - Software Packing (UPX)
- T1096 - Alternate Data Streams
- T1099 - Timestomping
- T1140 - Encode/Decode Data with certutil
- T1158 - Hidden Files
- Unloading Sysmon Driver
- Using Native Syscalls to Bypass AVs/EDRs
- Using Syscalls Directly from Visual Studio to Bypass AVs/EDRs
- Detecting Sysmon on the Victim Host
- Dumping GAL (Global Address List) from Outlook Web Application
- Enumerating Users without net, Services without sc, and Scheduled Tasks without schtasks
- README
- T1010 - Application Window Discovery
- T1087 - Account Discovery
- Using COM to Enumerate Hostname, Username, Domain, Network Drives
- NetNTLMv2 Hash Stealing using Outlook
- Password Spraying Outlook Web Access (Remote Shell)
- Phishing with GoPhish and DigitalOcean
- README
- T1187 - Forced Authentication
- Bypassing Malicious Macro Detections by Defeating Child-Parent Process Relationships
- Inject Macros from a Remote .dotm Template (DOCX with Macros)
- Phishing .slk (Excel)
- Phishing Embedded HTML Forms
- Phishing Embedded Internet Explorer
- Phishing OLE + .lnk
- Phishing: Replacing Embedded Video with Bogus Payload
- Phishing XLM Macro 4.0
- README
- T1137 - Office VBA Macros
- T1173 - DDE
- Empire Shells with NetNTLMv2 Relaying
- Lateral Movement via SMB Relaying by Abusing Lack of SMB Signing
- Lateral Movement with PsExec
- README
- Simple TCP Relaying with Netcat
- SSH Tunnelling / Port Forwarding
- T1028 - WinRM for Lateral Movement
- T1047 - WMI for Lateral Movement
- T1051 - Shared Webroot
- T1076 - RDP Hijacking for Lateral Movement
- T1175 - Distributed Component Object Model
- WMI + MSI Lateral Movement
- WMI + PowerShell Desired State Configuration Lateral Movement
- WMI via NewScheduledTask
- Office Templates
- README
- T1013 - AddMonitor
- T1015 - sethc
- T1035 - Service Execution
- T1053 - schtask
- T1122 - COM Hijacking
- T1128 - Netsh Helper DLL
- T1130 - Install Root Certificate
- T1131 - Auth Packages
- T1136 - Create Account
- T1138 - Application Shimming
- T1180 - Screensaver Hijack
- T1197 - BITS Jobs
- T1198 - Trust Provider Hijacking
- T1209 - Hijacking Time Providers
- Word Library Add-ins
- README
- T1038 - DLL Hijacking
- T1108 - Redundant Access
- T1134 - Access Token Manipulation
- T1183 - Image File Execution Options Injection
- Unquoted Service Paths
- Weak Service Permissions
- Windows NamedPipes Privilege Escalation