Repository navigation

#

countercept

Rust
3249
2 个月前

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Python
1029
6 年前

A helper script for unpacking and decompiling EXEs compiled from python code.

Python
963
1 年前

A PoC implementation for spoofing arbitrary call stacks when making sys calls (e.g. grabbing a handle via NtOpenProcess)

C++
513
4 个月前

Incident Response collection and processing scripts with automated reporting scripts

Shell
307
1 年前

A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

Python
225
8 年前

snake - a malware storage zoo

Shell
216
2 年前

Scripts for performing and detecting parent PID spoofing

PowerShell
146
5 年前

Data visualization for blue teams

Svelte
126
3 年前

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing detection techniques or other security research.

C
120
8 年前

https://blog.f-secure.com/hiding-malicious-code-with-module-stomping/

C++
120
6 年前

A spiritual .NET equivalent to the Gargoyle memory scanning evasion technique

C#
52
7 年前

ESF modular ingestion tool for development and research.

Objective-C
36
4 年前

AMSI detection PoC

C#
32
5 年前

A document tagging library

Rust
30
5 个月前

A triage data collection script for macOS

Shell
28
5 年前

RemotePSpy provides live monitoring of remote PowerShell sessions, which is particularly useful for older (pre-5.0) versions of PowerShell which do not have comprehensive logging facilities built in.

Python
19
5 年前

A higher-level wrapper on top of the official bson & mongodb crates.

Rust
17
9 个月前