Windows Events Attack Samples
-
Updated
Jan 24, 2023 - HTML
Windows Events Attack Samples
Weaponize DLL hijacking easily. Backdoor any function in any DLL.
Resources About Windows Security. 1100+ Open Source Tools. 3300+ Blog Post and Videos.
A desktop application that checks security-related settings and makes recommendations for improvements without requiring central device management or automated reporting.
🐟 PoC of a VBA macro spawning a process with a spoofed parent and command line.
List of Awesome Windows Security Resources
Active Directory pentesting tool for Linux. Automated Kerberoasting, AS-REP Roasting, ADCS/ESC exploitation, DCSync, BloodHound integration, and 40+ AD attack paths. ENS Alto / NIS2 / ISO 27001 compliance reports. No Windows required.
Open-source endpoint detection engine for Windows and Linux using ETW, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Manipulating and Abusing Windows Access Tokens.
Windows 11 secure group policy for standalone devices
Run a program as TrustedInstaller (SYSTEM)
Blue Hammer by Nightmare-Eclipse Vulnerability Documentation & Reimplementation.
🛡️ Security & Privacy Hardening Tool for Windows 11 25H2 — 630+ Settings, 7 Modules, BAVR Pattern.
Automated CIS Benchmark Compliance Remediation for Windows Server 2019 with Ansible
Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV heuristics through a layered stack of in-memory execution and obfuscation techniques.
Automated CIS Benchmark Compliance Remediation for Windows Server 2022 with Ansible
A collection of awesome ethical hacking and security related content!
I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrates how file extension spoofing can be used to evade detection.
Xploitra is a powerful reverse shell payload generator for educational and security testing. It offers customizable payloads with advanced obfuscation and session management, making it ideal for simulating real-world attack scenarios and assessing system security.
Add a description, image, and links to the windows-security topic page so that developers can more easily learn about it.
To associate your repository with the windows-security topic, visit your repo's landing page and select "manage topics."