Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
-
Updated
Oct 26, 2020 - XSLT
{{ message }}
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Bloodhound for Blue and Purple Teams
FudgeC2 - a command and control framework designed for team collaboration and post-exploitation activities.
This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.
Monitoring your Slack workspaces for sensitive information
Atomic Purple Team Framework and Lifecycle
The GitHub of Adversary Emulation Plans in JSON. Share SCYTHE threats with the community. #ThreatThursday adversary emulation plans are shared here.
Purple Teaming Attack & Hunt Lab - Terraform
See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)
Monitoring GitLab for sensitive data shared publicly
Bi-weekly hunting queries
PurpleSpray is an adversary simulation tool that executes password spray behavior under different scenarios and conditions with the purpose of generating attack telemetry in properly monitored Windows enterprise environments
Monitoring GitHub for sensitive data shared publicly
Supporting material for my presentation "Adversarial Threat Modelling — A Practical Approach to Purple Teaming in the Enterprise"
SCYTHE Purple Team Exercise Framework
Deceptive tradecraft should be fun and light, not stern and stressful. It is cool to be cute.
A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.
PowerShell script to get domain mail info and control status such as MX, SPF, DKIM, DMARC and StartTLS.
A purple team oriented cyber range deployed in AWS with Terraform
A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small HELK R&D lab in Azure.
PowerShell module to build a passphrase by rolling 5 dice against a wordlist - e.g. the one you can find at https://www.eff.org/dice.
PurpleSharpEnhanced is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments
Add a description, image, and links to the purpleteam topic page so that developers can more easily learn about it.
To associate your repository with the purpleteam topic, visit your repo's landing page and select "manage topics."