Highlights
- Pro
-
-
shell-setup Public
Forked from mttaggart/shell-setupRepo for automating shell config on new machines
-
A Dockerized build pipeline for custom Windows x64 shellcode
-
pisces Public
Forked from mjc-gh/piscesA tool for analyzing phishing attack sites
Go UpdatedDec 10, 2025 -
VM-Packages Public
Forked from mandiant/VM-PackagesChocolatey packages supporting the analysis environment projects FLARE-VM & Commando VM.
-
cazadora Public
Simple hunting script for suspicious M365 OAuth Apps
-
-
-
-
blue-jupyter Public
Forked from mttaggart/blue-jupyterJupyter Notebooks for the Blue Team
-
Slides for BSidesNYC 2024 - "When Apps Attack: Hunting Traitorware and Rogue Microsoft 365 Apps at the Small to Medium Business Scale"
-
tricon-2024-identity-crisis Public
Slides for Identity Crisis from TricCon 2024
1 UpdatedJul 28, 2024 -
SharpTokenFinder Public
C# implementation of TokenFinder. Steal M365 access tokens from Office Desktop apps
-
GraphRunner Public
Forked from dafthack/GraphRunnerA Post-exploitation Toolset for Interacting with the Microsoft Graph API
-
Identity Crisis: Combating M365 Account Takeovers at Scale (BSides Nashville 2024)
3 UpdatedMay 13, 2024 -
GraphSpy Public
Forked from RedByte1337/GraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI
-
-
pancakescon-2024 Public
How to Combat Microsoft365 Account Takeovers (while you're not out Thru-Hiking the Appalachian Trail)
2 UpdatedMar 25, 2024 -
wtfbins Public
Forked from mttaggart/wtfbinsWTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
-
Sandbox evasion (probably?) via BuildCommDCBAndTimeoutA PoC
-
Unprotect_Submission Public
Forked from Unprotect-Project/Unprotect_SubmissionRepository to publish your evasion techniques and contribute to the project
-
clarion Public
The clarion call tells you if someone is logging into an AitM proxy that is proxying your M365 login page
-
flare-vm Public
Forked from mandiant/flare-vmA collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.
-
SharpCollection Public
Forked from Flangvik/SharpCollectionNightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
2 UpdatedNov 29, 2023 -
-
merlin Public
Forked from Ne0nd0g/merlinMerlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
-
-
Terraform repo for "Cloudy with a Chance of Malware"
-
-
merlin-agent Public
Forked from Ne0nd0g/merlin-agent