_________________________
/ So, do you really think \
\ androids dream of us? / ________________________________
------------------------- < Anyways, I'm too hot for them. >
/ --------------------------------
/ \ . . .
/ \ . . . ` ,
__ \ .; . : .' : : : .
.'@@@@@@`./UooU \ i..`: i` i.i.,i i .
(@@@@@@@@@@)\__/ \ `,--.|i |i|ii|ii|i:
(@@@@@@@@) UooU\.'@@@@@@`.||'
`YY~~~~YY' \__/(@@@@@@@@@@)'
|| || (@@@@@@@@)
`YY~~~~YY'
|| ||
Gists of Interest
Gist | Description |
---|---|
elevator_decrypt_key.cpp | Unprotect the App-Bound Encryption Key via an RPC call to Google Chrome Elevation Service (PoC). |
Sharp7Zip.cs | Self-contained 7-Zip wrapper using SevenZipSharp & Costura.Fody. |
sspi.py | Minified version of Python SSPI lib stolen from @ly4k's Certipy. |
dllmain.cpp | From VMWSU.DLL Side Load to Malicious SSP (PoC). |
ImagePathNameSpoof.c | Spawn process with an arbitary DLL search order start directory (PoC). |
secretsdump-no-smb.patch | DCSync without SMB interaction (impacket-secretsdump) |
RemComObf.sh | Simple RemComSvc obfuscation (PoC). |
cfinder.py | Presets for @naksyn's Pyramid. |
generate.py | Dynamic shellcode runner based on @xpn's example. |
🐳 Docker Hub
Image | Alias |
---|---|
physmem2profit | docker run --rm -it -v `pwd`:/app/output --privileged snovvcrash/physmem2profit |
ollvm13 | docker run --rm -it -u `id -u` -v /tmp:/build -v `pwd`:/tmp snovvcrash/ollvm13 x86_64-w64-mingw32-clang |
divideandscan | docker run --rm -it --name das -v ~/.das:/root/.das -v `pwd`:/app -p 8050:8050 snovvcrash/divideandscan |
pcredz | docker run --rm -it --network host -v ~/.pcredz:/root/.pcredz snovvcrash/pcredz |
📈 Stats
You're visitor | |
Support |
DISCLAIMER
All the tools associated with this GitHub account are provided for educational and research purposes only. The owner of the account is not responsible for any illegal use of any of the related tooling.