Posts

Showing posts with the label Processes

Invisi-Shell - Shroud Your Powershell Script Inwards Manifestly Sight (Bypass All Powershell Safety Features)

Image
Hide your powershell script inwards obviously sight! Invisi-Shell bypasses all of Powershell safety features (ScriptBlock logging, Module logging, Transcription, AMSI) yesteryear hooking .Net assemblies. The claw is performed via CLR Profiler API. Work In Progress This is nevertheless a preliminary version intended equally a POC. The code industrial plant exclusively on x64 processes together with tested against Powershell V5.1. Usage Copy the compiled InvisiShellProfiler.dll from /x64/Release/ folder alongside the ii batch files from the root directory (RunWithPathAsAdmin.bat & RunWithRegistryNonAdmin.bat) to the same folder. Run either of the batch files (depends if yous bring local admin privelledges or not) Powershell console volition run. Exit the powershell using the leave of absence ascendance (DON'T CLOSE THE WINDOW) to permit the batch file to perform proper cleanup. Compilation Project was created alongside Visual Studio 2013. You should in...

Dirhunt V0.6.0 - Uncovering Spider Web Directories Without Bruteforce

Image
DEVELOPMENT BRANCH : The electrical current branch is a evolution version. Go to the stable issue past times clicking on the principal branch . Dirhunt is a spider web crawler optimize for search together with analyze directories . This tool tin forcefulness out let on interesting things if the server has the "index of" manner enabled. Dirhunt is also useful if the directory listing is non enabled. It detects directories alongside false 404 errors , directories where an empty index file has been created to enshroud things together with much more. $ dirhunt http://website.com/ Dirhunt does non operate beast force. But neither is it only a crawler . This tool is faster than others because it minimizes requests to the server. Generally, this tool takes between 5-30 seconds , depending on the website together with the server. Read to a greater extent than close how to use Dirhunt in the documentation . Features Process one or multiple sites at a time. P...

Dnspy - .Net Debugger In Addition To Assembly Editor

Image
dnSpy is a debugger too .NET assembly editor. You tin laissez passer on the axe purpose it to edit too debug assemblies fifty-fifty if you lot don't bring whatever source code available. Want to nation thanks? Click the star at the occur of the page. Or fork dnSpy too mail a PR! The next pictures demonstrate dnSpy inward action. It shows dnSpy editing too debugging a .NET EXE file, non source code. Features Debug .NET Framework, .NET Core too Unity game assemblies, no source code required Edit assemblies inward C# or Visual Basic or IL, too edit all metadata Light too nighttime themes Extensible, write your ain extension High DPI back upwards (per-monitor DPI aware) And much more, run into below dnSpy uses the ILSpy decompiler engine too the Roslyn (C# / Visual Basic) compiler too many other opened upwards source libraries, run into below for to a greater extent than info. Debugger Debug .NET Framework, .NET Core too Unity game assemblies, no source cod...

Process Hacker - A Free, Powerful, Multi-Purpose Tool That Helps Yous Monitor Arrangement Resources, Debug Software Together With Notice Malware

Image
H5N1 free, powerful, multi-purpose tool that helps y'all monitor organisation resources, debug software too honor malware. System requirements Windows seven or higher, 32-bit or 64-bit. Features A detailed overview of organisation action amongst highlighting. Graphs too statistics allow y'all apace to rail downwards resources hogs too runaway processes. Can't edit or delete a file? Discover which processes are using that file. See what programs accept active network connections, too unopen them if necessary. Get real-time information on disk access. View detailed stack traces amongst kernel-mode, WOW64 too .NET support. Go beyond services.msc: create, edit too command services. Small, portable too no installation required. 100% Free Software ( GPL v3 ) Building the project Requires Visual Studio (2017 or later). Execute build_release.cmd located inward the build directory to compile the projection or charge the ProcessHacker.sln too Pl...

Dcomrade - Powershell Script For Enumerating Vulnerable Dcom Applications

Image
DCOMrade is a Powershell script that is able to enumerate the possible vulnerable DCOM applications that mightiness allow for lateral movement, code execution, information exfiltration, etc. The script is cook to piece of employment amongst Powershell 2.0 but volition piece of employment amongst all versions to a higher house every bit well. The script currently supports the next Windows operating systems (both x86 in addition to x64): Microsoft Windows 7 Microsoft Windows 10 Microsoft Windows Server 2012 / 2012 R2 Microsoft Windows Server 2016 How it works The script was made based on the inquiry done past times Matt Nelson ( @enigma0x3 ), particularly the round 2 blogpost that goes into finding DCOM applications that mightiness endure useful for pentesters in addition to cherry teams. First a remote connective amongst the target organization is made, this connective is used throughout the script for a multitude of operations. H5N1 Powershell ascendance is executed on t...