Windows Events Attack Samples
-
Updated
Jan 24, 2023 - HTML
Windows Events Attack Samples
Weaponize DLL hijacking easily. Backdoor any function in any DLL.
Resources About Windows Security. 1100+ Open Source Tools. 3300+ Blog Post and Videos.
A desktop application that checks security-related settings and makes recommendations for improvements without requiring central device management or automated reporting.
🐟 PoC of a VBA macro spawning a process with a spoofed parent and command line.
List of Awesome Windows Security Resources
Open-source endpoint detection engine for Windows and Linux using ETW, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Active Directory pentesting tool for Linux. Automated Kerberoasting, AS-REP Roasting, ADCS/ESC exploitation, DCSync, BloodHound integration, and 40+ AD attack paths. ENS Alto / NIS2 / ISO 27001 compliance reports. No Windows required.
Manipulating and Abusing Windows Access Tokens.
Windows 11 secure group policy for standalone devices
Run a program as TrustedInstaller (SYSTEM)
Blue Hammer by Nightmare-Eclipse Vulnerability Documentation & Reimplementation.
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
Automated CIS Benchmark Compliance Remediation for Windows Server 2019 with Ansible
Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV heuristics through a layered stack of in-memory execution and obfuscation techniques.
Automated CIS Benchmark Compliance Remediation for Windows Server 2022 with Ansible
A collection of awesome ethical hacking and security related content!
I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrates how file extension spoofing can be used to evade detection.
Xploitra is a powerful reverse shell payload generator for educational and security testing. It offers customizable payloads with advanced obfuscation and session management, making it ideal for simulating real-world attack scenarios and assessing system security.
Add a description, image, and links to the windows-security topic page so that developers can more easily learn about it.
To associate your repository with the windows-security topic, visit your repo's landing page and select "manage topics."