top of page

Changes is the only thing which never change
IT news & Information Technology Comparison


Coercer
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods. Features: Lists...


ADFSpoof
Created by Doug Bienstock @doughsec while at Mandiant FireEye. ADFSpoof has two main functions: Given the EncryptedPFX blob from the AD...
Jenkins reverse shell
If you gain access to a jenkins script console you can use this to gain a reverse shell on the node. r = Runtime.getRuntime() p =...
Forwarding Ports
Sometimes, after gaining access to an endpoint there are local ports. Making these internal ports external routable can help for lateral...


Upgrading shell to meterpreter
Shells ( https://infinitelogins.com/tag/payloads/ ) After getting basic shell access to an endpoint a meterpreter is nicer to continue...
Enabling RDP
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f netsh...


iquidSnake
Liquid Snake is a program aimed at performing lateral movement against Windows systems without touching the disk. The tool relies on WMI...


PsExec
PsExec is a part of the Sysinternals suite of tools, which is a collection of utilities for managing and troubleshooting Windows systems....


PowerLessShell
Tool that uses MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. Install: git clone...


WMIOps
WMIOps is a powershell script that uses WMI to perform a variety of actions on hosts, local or remote, within a Windows environment....


crackmapexec
This is a great tool for pivoting in a Windows/Active Directory environment using credential pairs (username:password, username:hash). It...
Lateral Movement tools
WMIOps WMI remote commands PowerLessShell Remote PowerShell without PowerShell PsExec Light-weight telnet-replacement LiquidSnake ...
Symantec discovered an intrusion on April 11, 2024, involving suspicious Windows Management Instrumentation commands and registry dumps, using PowerShell to query Active Directory for services.
Symantec discovered an intrusion on April 11, 2024, involving suspicious Windows Management Instrumentation commands and registry dumps....


PowerLessShell
Tool that uses MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. Install: git clone...


WMIOps
WMIOps is a powershell script that uses WMI to perform a variety of actions on hosts, local or remote, within a Windows environment....
bottom of page