- Powershell Payload Delivery via DNS using Invoke-PowerCloud
- WIP: Masquerading Processes in Userland through _PEB
- Pentesting Cheatsheets
- T1055: Process Injection
- Phishing with MS Office
- T1003: Credential Dumping
- T1208: Kerberoasting
- T1134: Access Token Manipulation
- AV Bypass with Metasploit Templates and Custom Binaries
- Red Team Infrastructure
- File Smuggling with HTML and JavaScript
- Commandline Obfusaction
- T1027: Obfuscated Powershell Invocations
- SSH Tunnelling / Port Forwarding
- T1117: regsvr32
- T1187: Forced Authentication
- T1099: Timestomping
- T1196: Control Panel Item
- T1170: MSHTA
- T1191: CSMTP
- T1118: InstallUtil
- T1053: Schtask
- T1214: Credentials in Registry
- T1028: WinRM for Lateral Movement
- T1047: WMI for Lateral Movement
- T1035: Service Execution
- T1216: pubprn.vbs Signed Script Code Execution
- T1138: Application Shimming
- T1015: Sticky Keys
- T1131: Authentication Packages
- T1136: Create Account
- T1197: BITS Jobs
- T1122: COM Hijacking
- T1038: DLL Hijacking
- T1158: Hidden Files
- T1128: NetSh Helper DLL
- T1013: AddMonitor()
- T1108: WebShells
- T1051: Shared Webroot
- T1198: SIP & Trust Provider Hijacking
- T1180: Screensaver Hijack
- T1209: Hijacking Time Providers
- T1084: Abusing Windows Managent Instrumentation
- T1207: DCShadow
- T1076: RDP Hijacking for Lateral Movement with tscon
- T1140: Encode/Decode Data with Certutil
- Downloading File with Certutil
- T1183: Image File Execution Options Injection
- T1202: Forfiles Indirect Command Execution
- T1130: Installing Root Certificate
- T1096: Alternate Data Streams
- T1045: Packed Binaries
- T1174: Password Filter
- T1010: Application Window Discovery
- T1087: Account Discovery & Enumeration
- T1175: Lateral Movement via DCOM
- Powershell Empire 101
- PowerView: Active Directory Enumeration
- Powershell Constrained Language Mode ByPass
- Powershell Without Powershell.exe
- Detecting Sysmon on the Victim Host
- Unloading Sysmon Driver
- WMI + MSI Lateral Movement
- WMI + NewScheduledTaskAction Lateral Movement