💭
Thinking in graphs
OSCP|OSEP|CRTO|CRTE :: Sr. Penetration Tester / Red Team Operator :: Author of Pentester’s Promiscuous Notebook (PPN)
- (╮°-°)╮┳━━┳ ( ╯°□°)╯ ┻━━┻
- https://ppn.snovvcra.sh
- @snovvcrash
- @snovvcrash@infosec.exchange
_________________________/ So, do you really think \\ androids dream of us? / ________________________________ ------------------------- < Anyways, I'm too hot for them. > / -------------------------------- / \ . . . / \ . . . ` , __ \ .; . : .' : : : . .'@@@@@@`./UooU \ i..`: i` i.i.,i i . (@@@@@@@@@@)\__/ \ `,--.|i |i|ii|ii|i: (@@@@@@@@) UooU\.'@@@@@@`.||' `YY~~~~YY' \__/(@@@@@@@@@@)' || || (@@@@@@@@) `YY~~~~YY' || ||
Gists of Interest
Gist | Description |
---|---|
elevator_decrypt_key.cpp | Unprotect the App-Bound Encryption Key via an RPC call to Google Chrome Elevation Service (PoC). |
Sharp7Zip.cs | Self-contained 7-Zip wrapper using SevenZipSharp & Costura.Fody. |
sspi.py | Minified version of Python SSPI lib stolen from @ly4k's Certipy. |
dllmain.cpp | From VMWSU.DLL Side Load to Malicious SSP (PoC). |
ImagePathNameSpoof.c | Spawn process with an arbitary DLL search order start directory (PoC). |
secretsdump-no-smb.patch | DCSync without SMB interaction (impacket-secretsdump). |
RemComObf.sh | Simple RemComSvc obfuscation (PoC). |
cfinder.py | Presets for @naksyn's Pyramid. |
generate.py | Dynamic shellcode runner based on @xpn's example. |
🐳 Docker Hub
Image | Alias |
---|---|
physmem2profit | docker run --rm -it -v `pwd`:/app/output --privileged snovvcrash/physmem2profit |
ollvm13 | docker run --rm -it -u `id -u` -v /tmp:/build -v `pwd`:/tmp snovvcrash/ollvm13 x86_64-w64-mingw32-clang |
divideandscan | docker run --rm -it --name das -v ~/.das:/root/.das -v `pwd`:/app -p 8050:8050 snovvcrash/divideandscan |
pcredz | docker run --rm -it --network host -v ~/.pcredz:/root/.pcredz snovvcrash/pcredz |
📈 Stats
You're visitor | |
Support |
DISCLAIMER
All the tools associated with this GitHub account are provided for educational and research purposes only. The owner of the account is not responsible for any illegal use of any of the related tooling.
PinnedLoading
- WeaponizeKali.sh
WeaponizeKali.sh Public archiveCollection of extra pentest tools for Kali Linux
- DivideAndScan
DivideAndScan PublicDivide full port scan results and use it for targeted Nmap runs
- SharpDXWebcam
SharpDXWebcam PublicUtilizing DirectX and DShowNET assemblies to record video from a host's webcam
- MirrorDump
MirrorDump PublicForked fromCCob/MirrorDump
Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory
Something went wrong, please refresh the page to try again.
If the problem persists, check theGitHub status page orcontact support.
If the problem persists, check theGitHub status page orcontact support.