Files
mthcht-ThreatHunting-Keywords/Collection_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

263 KiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* /c start /min powershell -noprofile -w H -c *irw*.{0,1000}\s\/c\sstart\s\/min\spowershell\s\-noprofile\s\-w\sH\s\-c\s.{0,1000}irw.{0,1000}greyware_tool_keywordpowershellSuspicious PowerShell execution behavior often observed in FakeCaptcha phishing attemptsT1059.001 - T1027 - T1564.003TA0005 - TA0002 - TA0009N/AN/ACollectionhttps://x.com/malware_traffic/status/1884476331821326816/photo/210N/AN/A76N/AN/AN/AN/A45
3* all_in_one_enum.ps1*.{0,1000}\sall_in_one_enum\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z258
4* CarSeat.py *.{0,1000}\sCarSeat\.py\s.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10N/AN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z546
5* dll-installer.ps1*.{0,1000}\sdll\-installer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z872
6* GraphSpy.py*.{0,1000}\sGraphSpy\.py.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z1381
7* Invoke-WebRequest -Uri http://download.anydesk.com/AnyDesk.exe*.{0,1000}\sInvoke\-WebRequest\s\-Uri\shttp\:\/\/download\.anydesk\.com\/AnyDesk\.exe.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the Dispossessor ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A1753
8* process call create *cmd.exe /c powershell.exe -nop -w hidden -c *IEX ((new-object net.webclient).downloadstring('https://*.{0,1000}\sprocess\scall\screate\s.{0,1000}cmd\.exe\s\/c\spowershell\.exe\s\-nop\s\-w\shidden\s\-c\s.{0,1000}IEX\s\(\(new\-object\snet\.webclient\)\.downloadstring\(\'https\:\/\/.{0,1000}greyware_tool_keywordwmicThreat Actors ran the following command to download and execute a PowerShell payloadT1059.001 - T1059.003 - T1569.002 - T1021.006TA0002 - TA0005N/AMAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - DispossessorCollectionhttps://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF10N/AN/A1010N/AN/AN/AN/A2676
9* SendScreenshotToTelegram*.{0,1000}\sSendScreenshotToTelegram.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z3037
10* snaffler.py *.{0,1000}\ssnaffler\.py\s.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z3271
11* Volumiser.exe *.{0,1000}\sVolumiser\.exe\s.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z3678
12* -W Hidden -command *https://*Invoke-WebRequest*; iex $*.{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}https\:\/\/.{0,1000}Invoke\-WebRequest.{0,1000}\;\siex\s\$.{0,1000}greyware_tool_keywordpowershellA PowerShell process downloaded and launched a remote fileT1059.001 - T1105 - T1203TA0001 - TA0002Lumma StealerN/ACollectionN/A10N/AN/A88N/AN/AN/AN/A3685
13* -W Hidden -command *Invoke-WebRequest*https://*; iex $*.{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}Invoke\-WebRequest.{0,1000}https\:\/\/.{0,1000}\;\siex\s\$.{0,1000}greyware_tool_keywordpowershellA PowerShell process downloaded and launched a remote fileT1059.001 - T1105 - T1203TA0001 - TA0002Lumma StealerN/ACollectionN/A10N/AN/A88N/AN/AN/AN/A3686
14* -w hidden -ep bypass -nop -Command "iex ((New-Object System.Net.WebClient).DownloadString(*.{0,1000}\s\-w\shidden\s\-ep\sbypass\s\-nop\s\-Command\s\"iex\s\(\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(.{0,1000}greyware_tool_keywordpowershellsuspicious powershell command often used in recaptcha phishing campaign (run dialog)T1086 - T1105 - T1218.003 - T1569.002TA0002 - TA0009Lumma StealerN/ACollectionN/A10N/AN/A1010N/AN/AN/AN/A3687
15* win-key-killer.ps1*.{0,1000}\swin\-key\-killer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z3726
16*"HEHE YOU HAVE BEEN PWENED"*.{0,1000}\"HEHE\sYOU\sHAVE\sBEEN\sPWENED\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z3844
17*#CODED BY SMUKX*.{0,1000}\#CODED\sBY\sSMUKX.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z3926
18*$env:TEMP\winkeykey.txt*.{0,1000}\$env\:TEMP\\winkeykey\.txt.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z3964
19*./logger.sh * &> /dev/null && exit*.{0,1000}\.\/logger\.sh\s.{0,1000}\s\&\>\s\/dev\/null\s\&\&\sexit.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger10#linuxN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z4164
20*./snaffler_downloads*.{0,1000}\.\/snaffler_downloads.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10#linuxN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z4207
21*/.gspy/databases/*.{0,1000}\/\.gspy\/databases\/.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#linuxN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z5016
22*/.local/bin/graphspy*.{0,1000}\/\.local\/bin\/graphspy.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#linuxN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z5019
23*/all_in_one_enum.ps1*.{0,1000}\/all_in_one_enum\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z5279
24*/bin/kidlogger*.{0,1000}\/bin\/kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A5634
25*/Carseat.git*.{0,1000}\/Carseat\.git.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat11N/AN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z5955
26*/CarSeat.py -*.{0,1000}\/CarSeat\.py\s\-.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10N/AN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z5956
27*/CCob/Volumiser*.{0,1000}\/CCob\/Volumiser.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser11N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z5965
28*/com.webtrufflehog.json*.{0,1000}\/com\.webtrufflehog\.json.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z6154
29*/dll-installer.ps1*.{0,1000}\/dll\-installer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z6642
30*/download*mediafire.com/.{0,1000}\/download.{0,1000}mediafire\.com\/greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1083 - T1560TA0009 N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A6750
31*/download/fiddler/fiddler-everywhere-windows*.{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A6751
32*/EDR_Detector.git*.{0,1000}\/EDR_Detector\.git.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z6888
33*/EDR_Detector.rs*.{0,1000}\/EDR_Detector\.rs.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z6889
34*/etc/kidlogger*.{0,1000}\/etc\/kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A7008
35*/Fiddler Everywhere *.*.*.exe*.{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A7190
36*/github.com*.exe?raw=true*.{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7414
37*/github.com/*/archive/refs/tags/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7415
38*/github.com/*/raw/main/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7416
39*/github.com/*/raw/main/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7417
40*/github.com/*/raw/main/*.app*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7418
41*/github.com/*/raw/main/*.as*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7419
42*/github.com/*/raw/main/*.asc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7420
43*/github.com/*/raw/main/*.asp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7421
44*/github.com/*/raw/main/*.bash*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11#linuxgreyware tool - risks of False positive !910N/AN/AN/AN/A7422
45*/github.com/*/raw/main/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7423
46*/github.com/*/raw/main/*.beacon*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7424
47*/github.com/*/raw/main/*.bin*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7425
48*/github.com/*/raw/main/*.bpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7426
49*/github.com/*/raw/main/*.c*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7427
50*/github.com/*/raw/main/*.cer*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7428
51*/github.com/*/raw/main/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7429
52*/github.com/*/raw/main/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7430
53*/github.com/*/raw/main/*.cpp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7431
54*/github.com/*/raw/main/*.crt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7432
55*/github.com/*/raw/main/*.cs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7433
56*/github.com/*/raw/main/*.csh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7434
57*/github.com/*/raw/main/*.dat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7435
58*/github.com/*/raw/main/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7436
59*/github.com/*/raw/main/*.docm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7437
60*/github.com/*/raw/main/*.dos*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7438
61*/github.com/*/raw/main/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7439
62*/github.com/*/raw/main/*.go*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7440
63*/github.com/*/raw/main/*.gz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7441
64*/github.com/*/raw/main/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7442
65*/github.com/*/raw/main/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7443
66*/github.com/*/raw/main/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7444
67*/github.com/*/raw/main/*.js*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7445
68*/github.com/*/raw/main/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7446
69*/github.com/*/raw/main/*.log*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7447
70*/github.com/*/raw/main/*.mac*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7448
71*/github.com/*/raw/main/*.mam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7449
72*/github.com/*/raw/main/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7450
73*/github.com/*/raw/main/*.msp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7451
74*/github.com/*/raw/main/*.nexe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7452
75*/github.com/*/raw/main/*.nim*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7453
76*/github.com/*/raw/main/*.otm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7454
77*/github.com/*/raw/main/*.out*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7455
78*/github.com/*/raw/main/*.ova*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7456
79*/github.com/*/raw/main/*.pem*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7457
80*/github.com/*/raw/main/*.pfx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7458
81*/github.com/*/raw/main/*.pl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7459
82*/github.com/*/raw/main/*.plx*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7460
83*/github.com/*/raw/main/*.pm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7461
84*/github.com/*/raw/main/*.ppk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7462
85*/github.com/*/raw/main/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7463
86*/github.com/*/raw/main/*.psm1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7464
87*/github.com/*/raw/main/*.pub*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7465
88*/github.com/*/raw/main/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7466
89*/github.com/*/raw/main/*.pyc*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7467
90*/github.com/*/raw/main/*.pyo*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7468
91*/github.com/*/raw/main/*.rar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7469
92*/github.com/*/raw/main/*.raw*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7470
93*/github.com/*/raw/main/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7471
94*/github.com/*/raw/main/*.rgs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7472
95*/github.com/*/raw/main/*.RGS*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7473
96*/github.com/*/raw/main/*.run*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7474
97*/github.com/*/raw/main/*.scpt*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7475
98*/github.com/*/raw/main/*.script*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7476
99*/github.com/*/raw/main/*.sct*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7477
100*/github.com/*/raw/main/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7478
101*/github.com/*/raw/main/*.ssh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7479
102*/github.com/*/raw/main/*.sys*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7480
103*/github.com/*/raw/main/*.teamserver*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7481
104*/github.com/*/raw/main/*.temp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7482
105*/github.com/*/raw/main/*.tgz*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7483
106*/github.com/*/raw/main/*.tmp*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7484
107*/github.com/*/raw/main/*.vb*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7485
108*/github.com/*/raw/main/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7486
109*/github.com/*/raw/main/*.vbscript*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7487
110*/github.com/*/raw/main/*.ws*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7488
111*/github.com/*/raw/main/*.wsf*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7489
112*/github.com/*/raw/main/*.wsh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7490
113*/github.com/*/raw/main/*.X86*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7491
114*/github.com/*/raw/main/*.X86_64*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7492
115*/github.com/*/raw/main/*.xlam*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7493
116*/github.com/*/raw/main/*.xlm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7494
117*/github.com/*/raw/main/*.xlsm*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7495
118*/github.com/*/raw/main/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7496
119*/github.com/*/raw/refs/heads/*.7z*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7497
120*/github.com/*/raw/refs/heads/*.apk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7498
121*/github.com/*/raw/refs/heads/*.bat*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7499
122*/github.com/*/raw/refs/heads/*.cmd*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7500
123*/github.com/*/raw/refs/heads/*.com*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7501
124*/github.com/*/raw/refs/heads/*.cpl*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7502
125*/github.com/*/raw/refs/heads/*.dll*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7503
126*/github.com/*/raw/refs/heads/*.exe*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7504
127*/github.com/*/raw/refs/heads/*.hta*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7505
128*/github.com/*/raw/refs/heads/*.iso*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7506
129*/github.com/*/raw/refs/heads/*.jar*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7507
130*/github.com/*/raw/refs/heads/*.lnk*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7508
131*/github.com/*/raw/refs/heads/*.msi*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7509
132*/github.com/*/raw/refs/heads/*.pif*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7510
133*/github.com/*/raw/refs/heads/*.ps1*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7511
134*/github.com/*/raw/refs/heads/*.py*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7512
135*/github.com/*/raw/refs/heads/*.reg*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7513
136*/github.com/*/raw/refs/heads/*.scr*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7514
137*/github.com/*/raw/refs/heads/*.sh*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7515
138*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7516
139*/github.com/*/raw/refs/heads/*.vbs*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7517
140*/github.com/*/raw/refs/heads/*.zip*.{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A7518
141*/GraphSpy.git*.{0,1000}\/GraphSpy\.git.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy11N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z7622
142*/GraphSpy.py*.{0,1000}\/GraphSpy\.py.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy11N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z7623
143*/keylog.exe*.{0,1000}\/keylog\.exe.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z8343
144*/keylogger.exe*.{0,1000}\/keylogger\.exe.{0,1000}offensive_tool_keywordkeyloggerKeyboard recordingT1056.001TA0006 - TA0009N/AN/ACollectionhttps://github.com/uknowsec/keylogger11N/AN/A92140352021-05-19T08:33:58Z2020-11-10T07:15:50Z8349
145*/keylogger.git*.{0,1000}\/keylogger\.git.{0,1000}offensive_tool_keywordkeyloggerKeyboard recordingT1056.001TA0006 - TA0009N/AN/ACollectionhttps://github.com/uknowsec/keylogger11N/AN/A92140352021-05-19T08:33:58Z2020-11-10T07:15:50Z8351
146*/KidLogger.app/*.{0,1000}\/KidLogger\.app\/.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A8355
147*/kidlogger.desktop*.{0,1000}\/kidlogger\.desktop.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A8356
148*/master/windows/klog_main.cpp*.{0,1000}\/master\/windows\/klog_main\.cpp.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z8728
149*/opt/gspy_log.txt*.{0,1000}\/opt\/gspy_log\.txt.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#linux #logfileN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z9412
150*/peeping-client.exe*.{0,1000}\/peeping\-client\.exe.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom11N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z9592
151*/peeping-tom.app*.{0,1000}\/peeping\-tom\.app.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom11#macoskeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z9593
152*/peeping-tom.exe*.{0,1000}\/peeping\-tom\.exe.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom11N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z9594
153*/peeping-tom.git*.{0,1000}\/peeping\-tom\.git.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom11N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z9595
154*/Powershell-Scripts-for-Hackers-and-Pentesters*.{0,1000}\/Powershell\-Scripts\-for\-Hackers\-and\-Pentesters.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z9826
155*/pypi.org/project/GraphSpy*.{0,1000}\/pypi\.org\/project\/GraphSpy.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy11N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z10086
156*/pysnaffler.git*.{0,1000}\/pysnaffler\.git.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler11N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z10097
157*/reghivebackup.zip*.{0,1000}\/reghivebackup\.zip.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip11#registryN/A1010N/AN/AN/AN/A10321
158*/snaffler.py*.{0,1000}\/snaffler\.py.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler11N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z11454
159*/srv/kidlogger*.{0,1000}\/srv\/kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A11602
160*/usr/share/kidlogger*.{0,1000}\/usr\/share\/kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#linuxN/A1010N/AN/AN/AN/A12376
161*/Volumiser.exe*.{0,1000}\/Volumiser\.exe.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser11N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z12478
162*/Volumiser.git*.{0,1000}\/Volumiser\.git.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser11N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z12479
163*/Volumiser-maser.zip*.{0,1000}\/Volumiser\-maser\.zip.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser11N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z12480
164*/webtrufflehog.git*.{0,1000}\/webtrufflehog\.git.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog11N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z12552
165*/webtrufflehog.log*.{0,1000}\/webtrufflehog\.log.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z12553
166*/win-key-killer.ps1*.{0,1000}\/win\-key\-killer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z12621
167*[!] Please save this key as it will be required to decrypt the keylogs from the target!*.{0,1000}\[!\]\sPlease\ssave\sthis\skey\sas\sit\swill\sbe\srequired\sto\sdecrypt\sthe\skeylogs\sfrom\sthe\starget!.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z12950
168*[+] Keylog recieved, data written to keylog.txt!*.{0,1000}\[\+\]\sKeylog\srecieved,\sdata\swritten\sto\skeylog\.txt!.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z13207
169*[Ngrok Tunnel URL*.{0,1000}\[Ngrok\sTunnel\sURL.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z13492
170*\all_in_one_enum.ps1*.{0,1000}\\all_in_one_enum\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z13901
171*\dll-installer.ps1*.{0,1000}\\dll\-installer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z14982
172*\EDR_Detector.rs*.{0,1000}\\EDR_Detector\.rs.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector10N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z15221
173*\Fiddler Everywhere *.*.*.exe*.{0,1000}\\Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/10N/AN/A610N/AN/AN/AN/A15425
174*\GraphSpy.py*.{0,1000}\\GraphSpy\.py.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z15721
175*\keylog.cpp*.{0,1000}\\keylog\.cpp.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z16121
176*\keylog.exe*.{0,1000}\\keylog\.exe.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z16122
177*\keylogger.exe*.{0,1000}\\keylogger\.exe.{0,1000}offensive_tool_keywordkeyloggerKeyboard recordingT1056.001TA0006 - TA0009N/AN/ACollectionhttps://github.com/uknowsec/keylogger10N/AN/A92140352021-05-19T08:33:58Z2020-11-10T07:15:50Z16127
178*\keylogger.txt*.{0,1000}\\keylogger\.txt.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z16130
179*\KidLogger\*.{0,1000}\\KidLogger\\.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A16133
180*\KidLogger_is1*.{0,1000}\\KidLogger_is1.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#registryregistry1010N/AN/AN/AN/A16134
181*\peeping-client.exe*.{0,1000}\\peeping\-client\.exe.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z17181
182*\peeping-tom.exe*.{0,1000}\\peeping\-tom\.exe.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z17182
183*\peeping-tom-main*.{0,1000}\\peeping\-tom\-main.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z17183
184*\Powershell-Scripts-for-Hackers-and-Pentesters*.{0,1000}\\Powershell\-Scripts\-for\-Hackers\-and\-Pentesters.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z17388
185*\Program Files (x86)\KidLogger*.{0,1000}\\Program\sFiles\s\(x86\)\\KidLogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A17501
186*\pysnaffler\pysnaffler\*.{0,1000}\\pysnaffler\\pysnaffler\\.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z17694
187*\reg.exe* save HKLM*.{0,1000}\\reg\.exe.{0,1000}\ssave\sHKLM.{0,1000}greyware_tool_keywordregT1003.002 - T1564.001TA0006 - TA0010N/AN/ACollectionN/A10#registryN/A1010N/AN/AN/AN/A17882
188*\RegHiveBackup.cfg*.{0,1000}\\RegHiveBackup\.cfg.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip10N/AN/A1010N/AN/AN/AN/A17885
189*\reghivebackup.zip*.{0,1000}\\reghivebackup\.zip.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip10N/AN/A1010N/AN/AN/AN/A17886
190*\Root\InventoryApplicationFile\reghivebackup*.{0,1000}\\Root\\InventoryApplicationFile\\reghivebackup.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip10N/AN/A1010N/AN/AN/AN/A18096
191*\snaffler.py*.{0,1000}\\snaffler\.py.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z18921
192*\Software\Kidlogger*.{0,1000}\\Software\\Kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#registryregistry1010N/AN/AN/AN/A18957
193*\toms-server\keylog.txt*.{0,1000}\\toms\-server\\keylog\.txt.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z19388
194*\trix-back-gen.zip*.{0,1000}\\trix\-back\-gen\.zip.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z19424
195*\Volumiser.exe*.{0,1000}\\Volumiser\.exe.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z19631
196*\Volumiser.sln*.{0,1000}\\Volumiser\.sln.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z19632
197*\Volumiser\Program.cs*.{0,1000}\\Volumiser\\Program\.cs.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z19633
198*\webtrufflehog.log*.{0,1000}\\webtrufflehog\.log.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z19689
199*\webtrufflehog-main*.{0,1000}\\webtrufflehog\-main.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z19690
200*\Windows\Temp\sam.save*.{0,1000}\\Windows\\Temp\\sam\.save.{0,1000}greyware_tool_keywordrega copy of the registry hiveT1003.002TA0009N/AN/ACollectionN/A10#registryN/A1010N/AN/AN/AN/A19754
201*\win-key-killer.ps1*.{0,1000}\\win\-key\-killer\.ps1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z19779
202*\WOW6432Node\Kidlogger*.{0,1000}\\WOW6432Node\\Kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#registryregistry1010N/AN/AN/AN/A19859
203*\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x77\x68\x6f\x61\x6d\x69*.{0,1000}\\x2f\\x75\\x73\\x72\\x2f\\x62\\x69\\x6e\\x2f\\x77\\x68\\x6f\\x61\\x6d\\x69.{0,1000}offensive_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0006 - TA0007N/ABlack BastaCollectionN/A10N/AN/AN/A10N/AN/AN/AN/A19884
204*] Starting GraphSpy. Open in your browser by going to the url displayed below.*.{0,1000}\]\sStarting\sGraphSpy\.\sOpen\sin\syour\sbrowser\sby\sgoing\sto\sthe\surl\sdisplayed\sbelow\..{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#contentN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z20076
205*>Disk to VHD converter<*.{0,1000}\>Disk\sto\sVHD\sconverter\<.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A10#descriptionN/A84N/AN/AN/AN/A20378
206*>Disk2vhd<*.{0,1000}\>Disk2vhd\<.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A10#productnameN/A84N/AN/AN/AN/A20379
207*>RegHiveBackup<*.{0,1000}\>RegHiveBackup\<.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip10#productnameN/A1010N/AN/AN/AN/A20495
208*09b0fe289efa8c6364964bddedb339a7d43b0eaae912ef4c3f357325c6c55b61*.{0,1000}09b0fe289efa8c6364964bddedb339a7d43b0eaae912ef4c3f357325c6c55b61.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z21361
209*0aa81384c29ae395069a9d6bf226f1345c7909cdc7181c2c4f1c9015268e940d*.{0,1000}0aa81384c29ae395069a9d6bf226f1345c7909cdc7181c2c4f1c9015268e940d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z21419
210*0bin - encrypted pastebin*.{0,1000}0bin\s\-\sencrypted\spastebin.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net10#PastebinLikeN/A510N/AN/AN/AN/A21511
211*0d773444d899ab08f8aaee56dec0fb17928784dca205ef25af61a71bf4fb6e3f*.{0,1000}0d773444d899ab08f8aaee56dec0fb17928784dca205ef25af61a71bf4fb6e3f.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z21628
212*0DF38AD4-60AF-4F93-9C7A-7FB7BA692017*.{0,1000}0DF38AD4\-60AF\-4F93\-9C7A\-7FB7BA692017.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10#GUIDprojectN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z21671
213*0xthirteen/Carseat*.{0,1000}0xthirteen\/Carseat.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat11N/AN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z21856
214*15a2171b1424a78028131808a24d39d5f5383cfd4540ea360a74f9b7c752933d*.{0,1000}15a2171b1424a78028131808a24d39d5f5383cfd4540ea360a74f9b7c752933d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z22272
215*1ae56e7ebbdbbd3912b3bec2f08c065895e82492494c26d076cce466dd0572ad*.{0,1000}1ae56e7ebbdbbd3912b3bec2f08c065895e82492494c26d076cce466dd0572ad.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z22637
216*1ea81f89cfaaf2fe3273f042bb4eaafc1046fbc3ceb146b79eee8a898a189b45*.{0,1000}1ea81f89cfaaf2fe3273f042bb4eaafc1046fbc3ceb146b79eee8a898a189b45.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z22923
217*1fc325f3-c548-43db-a13f-8c460dda8381*.{0,1000}1fc325f3\-c548\-43db\-a13f\-8c460dda8381.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger10#GUIDprojectN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z23002
218*216244b421d1ebb05ea81496831a2893139d6e2329db77e39cd6a2dc08e703e8*.{0,1000}216244b421d1ebb05ea81496831a2893139d6e2329db77e39cd6a2dc08e703e8.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z23131
219*2236b69f5c5c266ca57af9f9a2fddd35a36b4dd4de5ee279f87d2bf2e769bc81*.{0,1000}2236b69f5c5c266ca57af9f9a2fddd35a36b4dd4de5ee279f87d2bf2e769bc81.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z23195
220*28f3463d7e6c3c5cc339f624712cee8e8277fffc2c6a4bf356cd4cb59ab4efce*.{0,1000}28f3463d7e6c3c5cc339f624712cee8e8277fffc2c6a4bf356cd4cb59ab4efce.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z23655
221*2e7780d7593f341c0b72ad38f91638cfbb917e7f9f342b3ffaa842d207d4ab85*.{0,1000}2e7780d7593f341c0b72ad38f91638cfbb917e7f9f342b3ffaa842d207d4ab85.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24011
222*3002cc4ccf57741919e563283d63b762f29512aafe16837b297c6d70e014bd04*.{0,1000}3002cc4ccf57741919e563283d63b762f29512aafe16837b297c6d70e014bd04.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24160
223*3170917f0dbe26d4a09283394af0b9a9e9724589cd650d0b451b2c834aab3bf6*.{0,1000}3170917f0dbe26d4a09283394af0b9a9e9724589cd650d0b451b2c834aab3bf6.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#filehashN/A1010N/AN/AN/AN/A24257
224*33b54c9b555472d471ff2eb145156d7212e13ad4282b020527267ca42c2afafe*.{0,1000}33b54c9b555472d471ff2eb145156d7212e13ad4282b020527267ca42c2afafe.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z24425
225*34b57458547e8ecd072caffdd5f390098197f2bef7cee067b0122b2c153f4b01*.{0,1000}34b57458547e8ecd072caffdd5f390098197f2bef7cee067b0122b2c153f4b01.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24498
226*35c64b018248a12e677777eab956c086212a2fe5d7206e76d66ac5dc9fa41103*.{0,1000}35c64b018248a12e677777eab956c086212a2fe5d7206e76d66ac5dc9fa41103.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24559
227*36a51b581592148e33c4f47c4e4f72710564595b6147b732e203d27a6d7dabb5*.{0,1000}36a51b581592148e33c4f47c4e4f72710564595b6147b732e203d27a6d7dabb5.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24612
228*39832c87758a620ccc75fcbdacee79993652fd81597ce79f52bab3f4b9abd2a5*.{0,1000}39832c87758a620ccc75fcbdacee79993652fd81597ce79f52bab3f4b9abd2a5.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z24833
229*3c9f2deb4c664d6321474815f4fefa2c80778fe2da2a9a35d1a31f2f9106bf96*.{0,1000}3c9f2deb4c664d6321474815f4fefa2c80778fe2da2a9a35d1a31f2f9106bf96.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z25046
230*3dca957edf214b435721c18bbacef52a660d618150453589bd95631eb92b5cc8*.{0,1000}3dca957edf214b435721c18bbacef52a660d618150453589bd95631eb92b5cc8.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z25121
231*3ec8a46dfacff51b3a19034479c2c68b74c92342e483295152754f939a8d1d31*.{0,1000}3ec8a46dfacff51b3a19034479c2c68b74c92342e483295152754f939a8d1d31.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#filehashN/A1010N/AN/AN/AN/A25185
232*417f92b83d18cb5d231496fde3d743a34d2f483c26cf831742e30cc11c3963bb*.{0,1000}417f92b83d18cb5d231496fde3d743a34d2f483c26cf831742e30cc11c3963bb.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z25417
233*41fe9889b428813cda89d017204555e013cf5c081122cd821f6c343ccc2ffcb7*.{0,1000}41fe9889b428813cda89d017204555e013cf5c081122cd821f6c343ccc2ffcb7.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z25461
234*4374b7f67ac23d9fc63fac8b9da7e279edd897ee5854d6a67c64ec648974e3fa*.{0,1000}4374b7f67ac23d9fc63fac8b9da7e279edd897ee5854d6a67c64ec648974e3fa.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z25565
235*450746e51e6f1369e7e73c5e2122d0ca81153d3a4c7bcec3d66266b15ee547f7*.{0,1000}450746e51e6f1369e7e73c5e2122d0ca81153d3a4c7bcec3d66266b15ee547f7.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#filehashN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z25682
236*49c9788a669f864351f347d5f13e34cab961a6bc88afe5f8a5e32e868a2fc81d*.{0,1000}49c9788a669f864351f347d5f13e34cab961a6bc88afe5f8a5e32e868a2fc81d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26012
237*4a613d768611d513d39de2212129c8fe56b77c016b0818584a3ca3cfd6a9bcaf*.{0,1000}4a613d768611d513d39de2212129c8fe56b77c016b0818584a3ca3cfd6a9bcaf.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z26044
238*4a852249475372d387ac1ba1c5ccd8b541dac4d89fb4ec51877cad81024a0c08*.{0,1000}4a852249475372d387ac1ba1c5ccd8b541dac4d89fb4ec51877cad81024a0c08.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26050
239*4b6df010ff6834f9d493d178079730ebd03f3fefd7a1e8da6c4456f2ed8d6296*.{0,1000}4b6df010ff6834f9d493d178079730ebd03f3fefd7a1e8da6c4456f2ed8d6296.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26131
240*4c230850f0fab974effc07d9ac7df6d11f2d49cac19d71da269d1c1d18e574e2*.{0,1000}4c230850f0fab974effc07d9ac7df6d11f2d49cac19d71da269d1c1d18e574e2.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26194
241*4cc3c88b175e7c6c9e881707ab3a6b956c7cbcb69a5f61d417d4736f054677b4*.{0,1000}4cc3c88b175e7c6c9e881707ab3a6b956c7cbcb69a5f61d417d4736f054677b4.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger10#filehashN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z26247
242*4fcf193202e55eff267792c86cea4098711b24d3fa0cca8e03027da2ddb3206a*.{0,1000}4fcf193202e55eff267792c86cea4098711b24d3fa0cca8e03027da2ddb3206a.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#filehashN/A1010N/AN/AN/AN/A26455
243*50C0BF9479EFC93FA9CF1AA99BD?CA923273B71A1*.{0,1000}50C0BF9479EFC93FA9CF1AA99BD\?CA923273B71A1.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z26528
244*50c461593a4ad6f09903a04e528de6991e745be1a7b444c002987348d921fcb0*.{0,1000}50c461593a4ad6f09903a04e528de6991e745be1a7b444c002987348d921fcb0.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26530
245*52b6c057a9e0af822cbe129053d2c2d3541bf6e9ef162432fae60fdbd7a2d0f0*.{0,1000}52b6c057a9e0af822cbe129053d2c2d3541bf6e9ef162432fae60fdbd7a2d0f0.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#filehashN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z26684
246*537fee794fe5532349360a40d90c0e0e37f9532b0101dbb17174e27cc4aa0d51*.{0,1000}537fee794fe5532349360a40d90c0e0e37f9532b0101dbb17174e27cc4aa0d51.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26738
247*568a162e78cabe48a7f30df47b2435b211549e9a7bc7a06f0802b6fc07b7cc94*.{0,1000}568a162e78cabe48a7f30df47b2435b211549e9a7bc7a06f0802b6fc07b7cc94.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z26958
248*59156b50c20d44f8757a3a53ebaf4f515b8eb86802ee51085ace7b1f714406ce*.{0,1000}59156b50c20d44f8757a3a53ebaf4f515b8eb86802ee51085ace7b1f714406ce.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z27173
249*5943462569081cec86ed241964fbccf91b4be608c2d647470b19afe31549adc5*.{0,1000}5943462569081cec86ed241964fbccf91b4be608c2d647470b19afe31549adc5.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z27180
250*5b5f70992a0d5a59176a7bfb43401d56ab3d250958378f1d913405040bf7cf54*.{0,1000}5b5f70992a0d5a59176a7bfb43401d56ab3d250958378f1d913405040bf7cf54.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z27341
251*5ba1b5f60649f253556fa044849ea7af38cef5337c5061f06004687e0862d6c3*.{0,1000}5ba1b5f60649f253556fa044849ea7af38cef5337c5061f06004687e0862d6c3.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z27359
252*5db320e5c5cbbc14478fc1d7c7ae33cfff92877fc585f83a3d7a981a00e9b4f4*.{0,1000}5db320e5c5cbbc14478fc1d7c7ae33cfff92877fc585f83a3d7a981a00e9b4f4.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z27519
253*5db3498c96a63ebbf02ce68726110bdc2111cdd4d8bbd3e75d37e8055e8cb3e7*.{0,1000}5db3498c96a63ebbf02ce68726110bdc2111cdd4d8bbd3e75d37e8055e8cb3e7.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z27520
254*63ec96c5-075f-4f22-92ec-cf28a2f70737*.{0,1000}63ec96c5\-075f\-4f22\-92ec\-cf28a2f70737.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#GUIDprojectkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z27941
255*6ef7a5a0d7eb7976141aa9d61242969b0dee3e8a7dddb6259c1bd539b68dcad8*.{0,1000}6ef7a5a0d7eb7976141aa9d61242969b0dee3e8a7dddb6259c1bd539b68dcad8.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z28654
256*71bda8ea-08bc-4ab1-9b40-614b167beb64*.{0,1000}71bda8ea\-08bc\-4ab1\-9b40\-614b167beb64.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#GUIDprojectkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z28848
257*73c49b77b6b2e4032eacfc94d5e5e2bd185fc8ce7eba23ed4ca6921ceb631614*.{0,1000}73c49b77b6b2e4032eacfc94d5e5e2bd185fc8ce7eba23ed4ca6921ceb631614.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z28998
258*7454351714f775b8391bc42fb94e929c87850debadc69d48a40ac7d9584e1211*.{0,1000}7454351714f775b8391bc42fb94e929c87850debadc69d48a40ac7d9584e1211.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z29038
259*7ce28732993dacc199e5f96517aa1d16305c86c623a0e17f9923838e3fa06133*.{0,1000}7ce28732993dacc199e5f96517aa1d16305c86c623a0e17f9923838e3fa06133.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z29644
260*7da1b05ebb0a51e4160ea04db4f70b6e710c14546d5a13169942e4d686bdc477*.{0,1000}7da1b05ebb0a51e4160ea04db4f70b6e710c14546d5a13169942e4d686bdc477.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z29694
261*828411d980e653c3fa63dd031839e52ae1800b4f29f3b03f7acad492811dce2b*.{0,1000}828411d980e653c3fa63dd031839e52ae1800b4f29f3b03f7acad492811dce2b.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#filehashN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z30052
262*8340cdf3b69ba92b47803f75eabb102d35454ef9676702ff1742c7136d9608de*.{0,1000}8340cdf3b69ba92b47803f75eabb102d35454ef9676702ff1742c7136d9608de.{0,1000}offensive_tool_keywordkeyloggerKeyboard recordingT1056.001TA0006 - TA0009N/AN/ACollectionhttps://github.com/uknowsec/keylogger10N/AN/A92140352021-05-19T08:33:58Z2020-11-10T07:15:50Z30112
263*85239f4abe215e87a147a6f63e8a281c2c3a687dcc45d430042c1e897de36696*.{0,1000}85239f4abe215e87a147a6f63e8a281c2c3a687dcc45d430042c1e897de36696.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#filehashN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z30241
264*85a88db7ae01c7735386630ef780fbabdf465b9b9fb1e30e5ea698b114a33540*.{0,1000}85a88db7ae01c7735386630ef780fbabdf465b9b9fb1e30e5ea698b114a33540.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z30273
265*868d0fe76c71f94336e0444d1b4ce6d7bdd2d0c71dcc2befa9ba1a1d3bb6d28f*.{0,1000}868d0fe76c71f94336e0444d1b4ce6d7bdd2d0c71dcc2befa9ba1a1d3bb6d28f.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z30316
266*89a687f0367983c98008e9bd2d82e6aa579e24f2d702b6912eeae74b21e85dc9*.{0,1000}89a687f0367983c98008e9bd2d82e6aa579e24f2d702b6912eeae74b21e85dc9.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#filehashN/A1010N/AN/AN/AN/A30544
267*8d352347e622b8ff6babf1a119266f59c1b14a48cebc4cb2cf84c00edd276fe3*.{0,1000}8d352347e622b8ff6babf1a119266f59c1b14a48cebc4cb2cf84c00edd276fe3.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#filehashkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z30817
268*920021c608185f95a4100ebec9e7c0fb4c67c1d192257ba9ac3430b2939762a3*.{0,1000}920021c608185f95a4100ebec9e7c0fb4c67c1d192257ba9ac3430b2939762a3.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger10#filehashN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z31154
269*922d41ca55d3fa150f1c8fdc1f030e2acf6c24fcbd0ce1cd1021aeffe29bf24c*.{0,1000}922d41ca55d3fa150f1c8fdc1f030e2acf6c24fcbd0ce1cd1021aeffe29bf24c.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#filehashN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z31169
270*93a9468ea39b4bb15148e4845593d36f0137c5a23de9045dc5596a302f873e16*.{0,1000}93a9468ea39b4bb15148e4845593d36f0137c5a23de9045dc5596a302f873e16.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z31274
271*94e25cf9677638da8ddfd84a2c15783e894de90331ed06e9786b1a46df1915fb*.{0,1000}94e25cf9677638da8ddfd84a2c15783e894de90331ed06e9786b1a46df1915fb.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z31355
272*975b49f84c3e34d26052f938c50aa5856cccbbdf32e9e4698cebba577ed10c8c*.{0,1000}975b49f84c3e34d26052f938c50aa5856cccbbdf32e9e4698cebba577ed10c8c.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z31528
273*9a33a8d19676646badef58d0a2db13dd763288a2a0fb8452ae2a9f826b27a234*.{0,1000}9a33a8d19676646badef58d0a2db13dd763288a2a0fb8452ae2a9f826b27a234.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z31720
274*9CD?F6D5878FC3AECF10761FD72371A2877F270D0*.{0,1000}9CD\?F6D5878FC3AECF10761FD72371A2877F270D0.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z31892
275*9D1C563E5228B2572F5CA14F0EC33?CA0DEDA3D57*.{0,1000}9D1C563E5228B2572F5CA14F0EC33\?CA0DEDA3D57.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z31916
276*9f9141f57f4d135a00557547091b73f9b13b0af2346082a243e65af90cb9be7e*.{0,1000}9f9141f57f4d135a00557547091b73f9b13b0af2346082a243e65af90cb9be7e.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z32088
277*A client side encrypted PasteBin*.{0,1000}A\sclient\sside\sencrypted\sPasteBin.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net10#content #PastebinLikeN/A510N/AN/AN/AN/A32125
278*a287b6d1ff18dab39efbf0b4c6937507f388923cbb47e66d72938aa87912bc20*.{0,1000}a287b6d1ff18dab39efbf0b4c6937507f388923cbb47e66d72938aa87912bc20.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z32336
279*a583acecdb43cd9b4806eddcf0582ec0cfd9281a2ff821b3d35c4d2dd6103eeb*.{0,1000}a583acecdb43cd9b4806eddcf0582ec0cfd9281a2ff821b3d35c4d2dd6103eeb.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z32539
280*a71a8916d6a82bcd0d80cc8150699754abdd4c165773438b9ed39515372a4ec8*.{0,1000}a71a8916d6a82bcd0d80cc8150699754abdd4c165773438b9ed39515372a4ec8.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z32652
281*ab36a5c1f20df8fb1b59154aa6aa83bba2d29a6925fb9ec134457e7d1c95bb7a*.{0,1000}ab36a5c1f20df8fb1b59154aa6aa83bba2d29a6925fb9ec134457e7d1c95bb7a.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z32973
282*abdullahansari1618@outlook.com*.{0,1000}abdullahansari1618\@outlook\.com.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#emailkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z33030
283*akoofbljmjeodfmdpjndmmnifglppjdi*.{0,1000}akoofbljmjeodfmdpjndmmnifglppjdi.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#browser_extensionidhttps://github.com/mthcht/awesome-lists/blob/41d3934b5b76aaf7555d980197d1e8b5c55f1fb3/Lists/Browser%20Extensions/browser_extensions_list.csv#L272102102024-12-29T23:26:35Z2024-12-28T19:53:09Z33775
284*API::installHook() - Windows keyboard hook could not be installed!*.{0,1000}API\:\:installHook\(\)\s\-\sWindows\skeyboard\shook\scould\snot\sbe\sinstalled!.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z33949
285*app.config['graph_spy_db_folder']*.{0,1000}app\.config\[\'graph_spy_db_folder\'\].{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#contentN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z33964
286*app.config['graph_spy_db_path']*.{0,1000}app\.config\[\'graph_spy_db_path\'\].{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#contentN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z33965
287*arp_mitm.py*.{0,1000}arp_mitm\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z34072
288*b2956027022f69baa93e6c55c69df6ace602d6ad61cb4ddfdaedd4c9be46d7b6*.{0,1000}b2956027022f69baa93e6c55c69df6ace602d6ad61cb4ddfdaedd4c9be46d7b6.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34571
289*b2b19b7cfc5f45ffcd83e6a099c40ba085cb86c4ab0ac4d0d4ad6aa8e0f40c4c*.{0,1000}b2b19b7cfc5f45ffcd83e6a099c40ba085cb86c4ab0ac4d0d4ad6aa8e0f40c4c.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34582
290*b4ac2390829f0e3a76c51692d27759ca7b83b4459c4707e86d59c72dbbbe36d3*.{0,1000}b4ac2390829f0e3a76c51692d27759ca7b83b4459c4707e86d59c72dbbbe36d3.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34718
291*b5cbcd477e65b4fad4c55e22043eda8859bab60bbdaad28386cf5a70f04299cd*.{0,1000}b5cbcd477e65b4fad4c55e22043eda8859bab60bbdaad28386cf5a70f04299cd.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z34805
292*b62764ff67244482f88ef117bf69d4ee51dc1691f6a62f3feab2dff8e94b9cdf*.{0,1000}b62764ff67244482f88ef117bf69d4ee51dc1691f6a62f3feab2dff8e94b9cdf.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34833
293*b7291585c934f4554e645642cebf82f663316646ccf4360f356ff535d2d6c969*.{0,1000}b7291585c934f4554e645642cebf82f663316646ccf4360f356ff535d2d6c969.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34910
294*b809230b5259568f275760187a0eb5c2cd00a6ac859d92e685036c1dfb797f0d*.{0,1000}b809230b5259568f275760187a0eb5c2cd00a6ac859d92e685036c1dfb797f0d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z34978
295*b88e406cbf20a830e357e89a3e3aa4210829777d43a5fb11d46e38a4220f4d9a*.{0,1000}b88e406cbf20a830e357e89a3e3aa4210829777d43a5fb11d46e38a4220f4d9a.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z35018
296*B948E25D061039D64115CFDE74D2FF4372E83765*.{0,1000}B948E25D061039D64115CFDE74D2FF4372E83765.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z35063
297*ba7aa4e5aba5fa90f17a2aca9cee62a2b01bb1fc91f6433643e48cdfa4b1c03d*.{0,1000}ba7aa4e5aba5fa90f17a2aca9cee62a2b01bb1fc91f6433643e48cdfa4b1c03d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z35125
298*bitsadmin /transfer *.{0,1000}bitsadmin\s\/transfer\s.{0,1000}greyware_tool_keywordbitsadminbitsadmin suspicious transferT1105 - T1041 - T1048TA0002 - TA0003 - TA0010N/ABlack Basta - Hive - Revil - Conti - MedusaCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A35991
299*bitsadmin /transfer debjob /download /priority normal \*\C$\Windows\*.dll.{0,1000}bitsadmin\s\/transfer\sdebjob\s\/download\s\/priority\snormal\s\\.{0,1000}\\C\$\\Windows\\.{0,1000}\.dllgreyware_tool_keywordbitsadminbitsadmin suspicious transferT1105 - T1041 - T1048TA0002 - TA0003 - TA0010N/ABlack Basta - Hive - Revil - Conti - MedusaCollectionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A35992
300*bWFsd2FyZQ==*.{0,1000}bWFsd2FyZQ\=\=.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z36430
301*c1c9047d94569bf28c91247cfa84cb49c5d49e37eaae46804663a6d1f45b615d*.{0,1000}c1c9047d94569bf28c91247cfa84cb49c5d49e37eaae46804663a6d1f45b615d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z36752
302*c3444ec251cca27dd59adbfbc995f095550b7e7e25623f46799e03584845b3b9*.{0,1000}c3444ec251cca27dd59adbfbc995f095550b7e7e25623f46799e03584845b3b9.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z36904
303*c3l3si4n/webtrufflehog*.{0,1000}c3l3si4n\/webtrufflehog.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog11N/AN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z36964
304*c4e9806596b8e6123a595395b0efe604176dfd2e767418fe4adf69c70de557b5*.{0,1000}c4e9806596b8e6123a595395b0efe604176dfd2e767418fe4adf69c70de557b5.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger10#filehashN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z37021
305*c7ef467eeb99aa4aae717d0e258019ab5b7e176da4906a135d86e78faa9251cc*.{0,1000}c7ef467eeb99aa4aae717d0e258019ab5b7e176da4906a135d86e78faa9251cc.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z37250
306*c8bdc5ce227d167f87797e8f7b3d91d24cd40c0925f5f6406085ad8cdf455617*.{0,1000}c8bdc5ce227d167f87797e8f7b3d91d24cd40c0925f5f6406085ad8cdf455617.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#filehashN/A1010N/AN/AN/AN/A37314
307*CarSeat: A junior Seatbelt\n*.{0,1000}CarSeat\:\sA\sjunior\sSeatbelt\\n.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#contentN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z37586
308*cc5b8ca570f2f1aa9aed761a466007e7bd4b807f823e5add1d10fb732a034e9c*.{0,1000}cc5b8ca570f2f1aa9aed761a466007e7bd4b807f823e5add1d10fb732a034e9c.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z37752
309*cd2e2beff40caf56b5102947d81e825f44b8df24d84f5dc49b1c850f4dca40a9*.{0,1000}cd2e2beff40caf56b5102947d81e825f44b8df24d84f5dc49b1c850f4dca40a9.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z37848
310*cdc1690245f3c8749c1ee9744540aa4df2b784f69cb425a967249c057b9799e8*.{0,1000}cdc1690245f3c8749c1ee9744540aa4df2b784f69cb425a967249c057b9799e8.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z37897
311*ce75ede7827b5a067bb11a5153e3046286251acaf1e92fd3edf4a46e506b5968*.{0,1000}ce75ede7827b5a067bb11a5153e3046286251acaf1e92fd3edf4a46e506b5968.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z37968
312*certoc.exe -GetCACAPS https://raw.githubusercontent.com*.{0,1000}certoc\.exe\s\-GetCACAPS\shttps\:\/\/raw\.githubusercontent\.com.{0,1000}greyware_tool_keywordcertocdownload from github with certocT1105 - T1566.001 - T1071.001TA0009 - TA0005N/AN/ACollectionhttps://lolbas-project.github.io/lolbas/Binaries/Certoc/10N/Alolbin89N/AN/AN/AN/A38026
313*certutil -urlcache -split -f http*.exe*.{0,1000}certutil\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.exe.{0,1000}greyware_tool_keywordcertutilCertutil download behavior observed by APT41 groupT1105 - T1566.001 - T1071.001TA0009 - TA0005N/AAPT41Collectionhttps://detect.fyi/playbook-hunting-chinese-apt-379a6b95049210N/Alolbin89N/AN/AN/AN/A38036
314*certutil.exe -urlcache -split -f *https://cdn.discordapp.com/attachments/*.{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\s.{0,1000}https\:\/\/cdn\.discordapp\.com\/attachments\/.{0,1000}greyware_tool_keywordcertutilLOLBAS execution - downloading payload from discord with certutilT1105 - T1218.010 - T1071.001 - T1036.005TA0009 - TA0002 - TA0005N/ACHRYSENE - GOLD SOUTHFIELDCollectionN/A10N/Alolbin1010N/AN/AN/AN/A38037
315*certutil.exe -urlcache -split -f http*.bat C:\ProgramData\*.{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.bat\sC\:\\ProgramData\\.{0,1000}greyware_tool_keywordcertutilCertutil download behavior observed by the Dispossessor ransomware groupT1105 - T1566.001 - T1071.001TA0009 - TA0005N/ADispossessorCollectionN/A10N/Alolbin1010N/AN/AN/AN/A38038
316*certutil.exe -urlcache -split -f http*.ps1 C:\ProgramData\*.{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.ps1\sC\:\\ProgramData\\.{0,1000}greyware_tool_keywordcertutilCertutil download behavior observed by the Dispossessor ransomware groupT1105 - T1566.001 - T1071.001TA0009 - TA0005N/ADispossessorCollectionN/A10N/Alolbin1010N/AN/AN/AN/A38039
317*certutil.exe -urlcache -split -f http*.vbs C:\ProgramData\*.{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.vbs\sC\:\\ProgramData\\.{0,1000}greyware_tool_keywordcertutilCertutil download behavior observed by the Dispossessor ransomware groupT1105 - T1566.001 - T1071.001TA0009 - TA0005N/ADispossessorCollectionN/A10N/Alolbin1010N/AN/AN/AN/A38040
318*certutil.exe -urlcache -split -f https://raw.githubusercontent.com/*.{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttps\:\/\/raw\.githubusercontent\.com\/.{0,1000}greyware_tool_keywordcertutilCertutil Download from githubT1105 - T1566.001 - T1071.001TA0009 - TA0005N/AN/ACollectionN/A10N/Alolbin89N/AN/AN/AN/A38041
319*change-windows10-mac-address.py*.{0,1000}change\-windows10\-mac\-address\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z38126
320*cmd /C reg export hkcu*.{0,1000}cmd\s\/C\sreg\sexport\shkcu.{0,1000}greyware_tool_keywordregexporting registry keysT1012TA0009N/AN/ACollectionhttps://blog.talosintelligence.com/uat-5647-romcom/10#registryN/A56N/AN/AN/AN/A38402
321*cmd /C reg export hklm*.{0,1000}cmd\s\/C\sreg\sexport\shklm.{0,1000}greyware_tool_keywordregexporting registry keysT1012TA0009N/AN/ACollectionhttps://blog.talosintelligence.com/uat-5647-romcom/10#registryN/A78N/AN/AN/AN/A38403
322*cmd.exe* /c echo curl https://* --output "%temp%* --ssl no-revoke --insecure --location > "%temp%*.{0,1000}cmd\.exe.{0,1000}\s\/c\secho\scurl\shttps\:\/\/.{0,1000}\s\-\-output\s\"\%temp\%.{0,1000}\s\-\-ssl\sno\-revoke\s\-\-insecure\s\-\-location\s\>\s\"\%temp\%.{0,1000}greyware_tool_keywordcurlpotential suspicious curl command - downloading payload in the temp directoryT1105 - T1059.003TA0005N/AN/ACollectionhttps://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/10N/AN/A1010N/AN/AN/AN/A38464
323*codeload.github.com/*.{0,1000}codeload\.github\.com\/.{0,1000}greyware_tool_keywordgithubGithub executables download initiated - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A38576
324*copy *NTDS\NTDS.dit*Temp*.{0,1000}copy\s.{0,1000}NTDS\\NTDS\.dit.{0,1000}Temp.{0,1000}greyware_tool_keywordcopycopy the NTDS.dit file from a Volume Shadow Copy which contains sensitive Active Directory data including password hashes for all domain usersT1003.003TA0009N/AN/ACollectionN/A10N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A38875
325*copy *sam.hive \\*.{0,1000}copy\s.{0,1000}sam\.hive\s\\\\.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A38877
326*copy *system.hive \\*.{0,1000}copy\s.{0,1000}system\.hive\s\\\\.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A38878
327*csvde -f *.{0,1000}csvde\s\-f\s.{0,1000}greyware_tool_keywordcsvdeexports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) formatT1005TA0009 - TA0007N/AN/ACollectionhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11)10N/AN/A99N/AN/AN/AN/A39175
328*csvde -r * -f *.{0,1000}csvde\s\-r\s.{0,1000}\s\-f\s.{0,1000}greyware_tool_keywordcsvdeexports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) formatT1005TA0009 - TA0007N/AN/ACollectionhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11)10N/AN/A99N/AN/AN/AN/A39176
329*csvde.exe -f *.{0,1000}csvde\.exe\s\-f\s.{0,1000}greyware_tool_keywordcsvdeexports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) formatT1005TA0009 - TA0007N/AN/ACollectionhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11)10N/AN/A99N/AN/AN/AN/A39177
330*csvde.exe -r * -f *.{0,1000}csvde\.exe\s\-r\s.{0,1000}\s\-f\s.{0,1000}greyware_tool_keywordcsvdeexports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) formatT1005TA0009 - TA0007N/AN/ACollectionhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11)10N/AN/A99N/AN/AN/AN/A39178
331*csvde.exe" -f *.{0,1000}csvde\.exe\"\s\-f\s.{0,1000}greyware_tool_keywordcsvdeexports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) formatT1005TA0009 - TA0007N/AN/ACollectionhttps://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11)10N/AN/A99N/AN/AN/AN/A39179
332*curl https://termbin.com/*.{0,1000}curl\shttps\:\/\/termbin\.com\/.{0,1000}greyware_tool_keywordtermbin.comaccessing paste raw contentT1119TA0009N/AN/ACollectiontermbin.com10#PastebinLikeN/A88N/AN/AN/AN/A39208
333*curl*nopaste.net*.{0,1000}curl.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingservice #linuxN/A810N/AN/AN/AN/A39221
334*d3a7210d3999176aaea1f64927668d443bffbd764fe113e2869b1ad03c2d3013*.{0,1000}d3a7210d3999176aaea1f64927668d443bffbd764fe113e2869b1ad03c2d3013.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z39612
335*D3DF3F32716042404798E3E9D691ACED2F78BD?D5*.{0,1000}D3DF3F32716042404798E3E9D691ACED2F78BD\?D5.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z39628
336*d62a0e8ea863d3812dcbf3927534db6b2a82223f2bfd2c374c7263be98b855f1*.{0,1000}d62a0e8ea863d3812dcbf3927534db6b2a82223f2bfd2c374c7263be98b855f1.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#filehashN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z39780
337*df68fb1553a6d135354adb6d2cc68ea5b0b63569e8d2c6bf5659869cf94ae4cc*.{0,1000}df68fb1553a6d135354adb6d2cc68ea5b0b63569e8d2c6bf5659869cf94ae4cc.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z40818
338*disk2vhd.exe*.{0,1000}disk2vhd\.exe.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41032
339*Disk2vhd.zip*.{0,1000}Disk2vhd\.zip.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41033
340*disk2vhd64.exe*.{0,1000}disk2vhd64\.exe.{0,1000}greyware_tool_keywordDisk2vhdconvert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for CollectionT1560.002 - T1012 - T1560.003TA0005 - TA0009N/AN/ACollectionN/A11N/AN/A84N/AN/AN/AN/A41034
341*DNS-Tunnel-Keylogger*.{0,1000}DNS\-Tunnel\-Keylogger.{0,1000}offensive_tool_keywordDNS-Tunnel-KeyloggerKeylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokesT1056.001 - T1048.003TA0009 - TA0011N/AN/ACollectionhttps://github.com/Geeoon/DNS-Tunnel-Keylogger11N/AN/A93273402024-06-16T19:47:36Z2024-01-10T17:25:58Z41290
342*docker run */.config/pcopy*.{0,1000}docker\srun\s.{0,1000}\/\.config\/pcopy.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingservice #linuxN/A810N/AN/AN/AN/A41328
343*download keylog.exe*.{0,1000}download\skeylog\.exe.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z41454
344*dpapi.py backupkeys -t */*@*.{0,1000}dpapi\.py\sbackupkeys\s\-t\s.{0,1000}\/.{0,1000}\@.{0,1000}greyware_tool_keyworddpapi.pythe command is used to extract the Data Protection API (DPAPI) backup keys from a target system. DPAPI is a Windows API that provides data protection services to secure sensitive data. such as private keys. passwords. and other secrets. By obtaining the DPAPI backup keys. an attacker can potentially decrypt sensitive data stored on the target system or impersonate users. gaining unauthorized access to other systems and resources.T1552.006TA0009N/AN/ACollectionN/A10N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A41497
345*e2bff960e45f419ca14338dcdefdcfe25378bc5efa56adfb762ebca92847d86f*.{0,1000}e2bff960e45f419ca14338dcdefdcfe25378bc5efa56adfb762ebca92847d86f.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z41922
346*e49c11f8f47b6fe4c3810ad8b5a241638983d7e60d240f70859fd4b7a887c4d6*.{0,1000}e49c11f8f47b6fe4c3810ad8b5a241638983d7e60d240f70859fd4b7a887c4d6.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z42051
347*e58c52c3eb69dc4b6cf3a73a42c7a9bc3adc4d0e4728a2a8744715fc730f8b9d*.{0,1000}e58c52c3eb69dc4b6cf3a73a42c7a9bc3adc4d0e4728a2a8744715fc730f8b9d.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z42121
348*e803b7023dfdcb1d73de9a04be5222269b020ada4fcc97ca19ef877c55a51c28*.{0,1000}e803b7023dfdcb1d73de9a04be5222269b020ada4fcc97ca19ef877c55a51c28.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z42310
349*ebef8a0206bb0550926511265edc977c0a75de6dd8a03be4e228cf708ac64c24*.{0,1000}ebef8a0206bb0550926511265edc977c0a75de6dd8a03be4e228cf708ac64c24.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z42594
350*EC54E?F8D79BF30B63C5249AF7A8A3C652595B923*.{0,1000}EC54E\?F8D79BF30B63C5249AF7A8A3C652595B923.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z42629
351*ec6e3c3f97578eeeb27f891b19c4504e038e0488293eb1f3c50d3bdc2f30b017*.{0,1000}ec6e3c3f97578eeeb27f891b19c4504e038e0488293eb1f3c50d3bdc2f30b017.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z42638
352*EDR Detector by trickster0*.{0,1000}EDR\sDetector\sby\strickster0.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector10N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z42823
353*EDR_Detection.exe*.{0,1000}EDR_Detection\.exe.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z42824
354*EDR_Detector.7z*.{0,1000}EDR_Detector\.7z.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z42825
355*EDR_Detector-master*.{0,1000}EDR_Detector\-master.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z42826
356*Exfiltrate::exfilLogs()*.{0,1000}Exfiltrate\:\:exfilLogs\(\).{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z43529
357*f0037d99bc3119fc613d304af20599e8c791b1c99208d5d452a01738777f7b49*.{0,1000}f0037d99bc3119fc613d304af20599e8c791b1c99208d5d452a01738777f7b49.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#filehashN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z43673
358*f4c91aebc3bbf867adc0ade2b4d82ffd1753a396143ce8e462b6460736efdbfd*.{0,1000}f4c91aebc3bbf867adc0ade2b4d82ffd1753a396143ce8e462b6460736efdbfd.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z43986
359*f572574e8f466040330510743d57e07ac795ed8caa62856f3efd2bff4f69793d*.{0,1000}f572574e8f466040330510743d57e07ac795ed8caa62856f3efd2bff4f69793d.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#filehashN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z44031
360*f59b24c1d84e1bbb4c0dc2677bb4010b474eb36a62c54ed1fbbf04d05aaf6a22*.{0,1000}f59b24c1d84e1bbb4c0dc2677bb4010b474eb36a62c54ed1fbbf04d05aaf6a22.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z44043
361*f8ffdb3b2c1b6172387a0e776a6f400c5117a0e525a3456465e3de4614555c10*.{0,1000}f8ffdb3b2c1b6172387a0e776a6f400c5117a0e525a3456465e3de4614555c10.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z44273
362*faaafe6256f59d72d96a71d7c12dccb964338c7ef8b9dbf359503ccd2ce79e41*.{0,1000}faaafe6256f59d72d96a71d7c12dccb964338c7ef8b9dbf359503ccd2ce79e41.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z44384
363*fbe18d97dcbd4ee2b6d3d9457142595613cb86a3f59fc7a54f52731925e5026e*.{0,1000}fbe18d97dcbd4ee2b6d3d9457142595613cb86a3f59fc7a54f52731925e5026e.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#filehashkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z44529
364*fde28cc5a25646c7b2579cd11a6914077500fabb172f8b44fd56bf9cfbad0511*.{0,1000}fde28cc5a25646c7b2579cd11a6914077500fabb172f8b44fd56bf9cfbad0511.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#filehashN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z44697
365*from pysnaffler.rules.constants import *.{0,1000}from\spysnaffler\.rules\.constants\simport\s.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z45333
366*from pysnaffler.rules.rule import SnaffleRule*.{0,1000}from\spysnaffler\.rules\.rule\simport\sSnaffleRule.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z45334
367*from pysnaffler.ruleset import SnafflerRuleSet*.{0,1000}from\spysnaffler\.ruleset\simport\sSnafflerRuleSet.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z45335
368*from pysnaffler.scanner import SnafflerScanner*.{0,1000}from\spysnaffler\.scanner\simport\sSnafflerScanner.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z45336
369*from pysnaffler.snaffler import *.{0,1000}from\spysnaffler\.snaffler\simport\s.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z45337
370*get_dpapi_masterkeys(*.{0,1000}get_dpapi_masterkeys\(.{0,1000}offensive_tool_keywordCarseatPython implementation of GhostPack Seatbelt situational awareness toolT1012 - T1082 - T1087 - T1124 - T1217TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/0xthirteen/Carseat10#contentN/A83257212024-11-12T19:37:38Z2024-11-08T02:08:53Z45631
371*Get-AndDisplayInformation -ClassName "Win32_BIOS"*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_BIOS\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45870
372*Get-AndDisplayInformation -ClassName "Win32_ComputerSystem" -PropertyFilter UserName*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_ComputerSystem\"\s\-PropertyFilter\sUserName.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45871
373*Get-AndDisplayInformation -ClassName "Win32_ComputerSystem"*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_ComputerSystem\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45872
374*Get-AndDisplayInformation -ClassName "Win32_Desktop"*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Desktop\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45873
375*Get-AndDisplayInformation -ClassName "Win32_LocalTime"*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LocalTime\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45874
376*Get-AndDisplayInformation -ClassName "Win32_LogicalDisk" -PropertyFilter DeviceID,DriveType,ProviderName,VolumeName,Size,FreeSpace,PSComputerName*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LogicalDisk\"\s\-PropertyFilter\sDeviceID,DriveType,ProviderName,VolumeName,Size,FreeSpace,PSComputerName.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45875
377*Get-AndDisplayInformation -ClassName "Win32_LogonSession"*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LogonSession\".{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45876
378*Get-AndDisplayInformation -ClassName "Win32_OperatingSystem" -PropertyFilter Build*,OSType,ServicePack**.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_OperatingSystem\"\s\-PropertyFilter\sBuild.{0,1000},OSType,ServicePack.{0,1000}.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45877
379*Get-AndDisplayInformation -ClassName "Win32_OperatingSystem" -PropertyFilter user*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_OperatingSystem\"\s\-PropertyFilter\suser.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45878
380*Get-AndDisplayInformation -ClassName "Win32_Processor" -PropertyFilter **.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Processor\"\s\-PropertyFilter\s.{0,1000}.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45879
381*Get-AndDisplayInformation -ClassName "Win32_QuickFixEngineering" -PropertyFilter HotFixId*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_QuickFixEngineering\"\s\-PropertyFilter\sHotFixId.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45880
382*Get-AndDisplayInformation -ClassName "Win32_Service" -PropertyFilter Status,Name,DisplayName*.{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Service\"\s\-PropertyFilter\sStatus,Name,DisplayName.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z45881
383*Get-VolumeShadowCopy *.{0,1000}Get\-VolumeShadowCopy\s.{0,1000}offensive_tool_keywordPowersploitPowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of filesT1003 - T1103 - T1213TA0006 - TA0009 - TA0010N/ADispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - TurlaCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A46320
384*github.com/SafeJKA/Kidlogger*.{0,1000}github\.com\/SafeJKA\/Kidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11N/AN/A1010N/AN/AN/AN/A46439
385*graphspy -i *.{0,1000}graphspy\s\-i\s.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z46693
386*GraphSpy.GraphSpy:main*.{0,1000}GraphSpy\.GraphSpy\:main.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10#contentN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z46694
387*GraphSpy-master.zip*.{0,1000}GraphSpy\-master\.zip.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy11N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z46695
388*HEHE - YOU HAVE BEEN PWENED*.{0,1000}HEHE\s\-\sYOU\sHAVE\sBEEN\sPWENED.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z47083
389*http://pastie.org/p/*/raw*.{0,1000}http\:\/\/pastie\.org\/p\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordpastie.orgaccessing paste raw contentT1119TA0009N/AN/ACollectionhttp://pastie.org/11#PastebinLikeN/A88N/AN/AN/AN/A47503
390*http://temp.sh/*/*.{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000}greyware_tool_keywordtemp.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47519
391*http://zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd.onion*.{0,1000}http\:\/\/zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd\.onion.{0,1000}greyware_tool_keywordzerobin.netaccessing paste raw contentT1119TA0009N/AN/ACollectionhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A47545
392*https://*.app.github.dev/*.{0,1000}https\:\/\/.{0,1000}\.app\.github\.dev\/.{0,1000}greyware_tool_keywordgithubaccess to a GitHub Codespace environment - Github Codespaces have a public port forwarding option allowing you to make your server available for the public.T1071 - T1572TA0001 - TA0005N/AN/ACollectionhttps://detect.fyi/how-threat-actors-use-github-bd991c11ed3701N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A47587
393*https://*.fex.net/download/*.{0,1000}https\:\/\/.{0,1000}\.fex\.net\/download\/.{0,1000}greyware_tool_keywordfex.nethosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/ACollectionhttps://fex.net11#filehostingservicedownloading a file1010N/AN/AN/AN/A47595
394*https://*.trycloudflare.com*.{0,1000}https\:\/\/.{0,1000}\.trycloudflare\.com.{0,1000}greyware_tool_keywordtrycloudflare.comAttackers abuse this service to expose malicious servers on a *.trycloudflare.com subdomainT1567.002 - T1102 - T1071.001 - T1036TA0001 - TA0005 - TA0009N/AN/ACollectionhttps://lots-project.com/site/2a2e747279636c6f7564666c6172652e636f6d01N/AN/A88N/AN/AN/AN/A47617
395*https://0bin.net/paste/*+*.{0,1000}https\:\/\/0bin\.net\/paste\/.{0,1000}\+.{0,1000}greyware_tool_keyword0bin.netAccessing a paste on 0bin.netT1213 - T1190TA0001 - TA0009 - TA0010N/AN/ACollectionhttps://0bin.net11#PastebinLikeN/A510N/AN/AN/AN/A47631
396*https://1ty.me/*.{0,1000}https\:\/\/1ty\.me\/.{0,1000}greyware_tool_keyword1ty.metemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AN/ACollectionhttps://1ty.me11#PastebinLikedownloading or uploading data1010N/AN/AN/AN/A47645
397*https://anonfiles.com/*/*.{0,1000}https\:\/\/anonfiles\.com\/.{0,1000}\/.{0,1000}greyware_tool_keywordanonfiles.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHubCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A47653
398*https://bayfiles.com/*.{0,1000}https\:\/\/bayfiles\.com\/.{0,1000}greyware_tool_keywordbayfileshosting site abused by attackers - blocked site in a lot of countriesT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ACyClopsCollectionN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47684
399*https://bitbucket.org/*/downloads/*.bat*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.bat.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47688
400*https://bitbucket.org/*/downloads/*.dll*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47689
401*https://bitbucket.org/*/downloads/*.dll*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47690
402*https://bitbucket.org/*/downloads/*.exe*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47691
403*https://bitbucket.org/*/downloads/*.ps1*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.ps1.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47692
404*https://bitbucket.org/*/downloads/*.rar*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.rar.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47693
405*https://bitbucket.org/*/downloads/*.zip*.{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.zip.{0,1000}greyware_tool_keywordbitbucket.orglegitimate hosting platform abused by malwares like lummastealerT1213 - T1102TA0009Lumma StealerN/ACollectionN/A01#filehostingserviceN/A57N/AN/AN/AN/A47694
406*https://dropmefiles.com/*.{0,1000}https\:\/\/dropmefiles\.com\/.{0,1000}greyware_tool_keyworddropmefiles.comtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AMallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice SocietyCollectionhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C4811#filehostingservicedownloading files url86504512025-04-19T17:43:15Z2023-05-02T16:17:48Z47749
407*https://easyupload.io/*.{0,1000}https\:\/\/easyupload\.io\/.{0,1000}greyware_tool_keywordeasyupload.iofile hosting platform abused by attackers to host malicious - url used when downloading a file on the siteT1567.002 - T1071.001 - T1041 - T1036.002TA0009N/ABlack BastaCollectionN/A11#filehostingserviceN/A810N/AN/AN/AN/A47751
408*https://file.io/*.{0,1000}https\:\/\/file\.io\/.{0,1000}greyware_tool_keywordfile.ioInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - ContiCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47761
409*https://filebin.net/*.{0,1000}https\:\/\/filebin\.net\/.{0,1000}greyware_tool_keywordfilebin.netfile hosting platform abused by attackers to host malicious file - raw access and api availableT1119TA0009 - TA0010N/AN/ACollectionhttps://filebin.net11#filehostingserviceN/A88N/AN/AN/AN/A47763
410*https://files.catbox.moe/*https:\/\/files\.catbox\.moe\/[^\s\n]+greyware_tool_keywordcatbox.moeThe cutest free file host you've ever seen - abused by threat actorsT1560.001 - T1190 - T1102 - T1027.002TA0001 - TA0005 - TA0042N/AN/ACollectionhttps://files[.]catbox.moe11#filehostingserviceN/A910N/AN/AN/AN/A47764
411*https://media.discordapp.net/attachments/*.bat*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.bat.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47821
412*https://media.discordapp.net/attachments/*.exe*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.exe.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47822
413*https://media.discordapp.net/attachments/*.hta*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.hta.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47823
414*https://media.discordapp.net/attachments/*.iso*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.iso.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47824
415*https://media.discordapp.net/attachments/*.jar*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.jar.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47825
416*https://media.discordapp.net/attachments/*.msi*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.msi.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47826
417*https://media.discordapp.net/attachments/*.py*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.py.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47827
418*https://media.discordapp.net/attachments/*.vbs*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.vbs.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47828
419*https://media.discordapp.net/attachments/*.zip*.{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.zip.{0,1000}greyware_tool_keyworddiscordDownloading discord executables and archives attachmentsT1189TA0001 - TA0009N/AN/ACollectionN/A11N/AN/A69N/AN/AN/AN/A47829
420*https://mega.nz/file/*.{0,1000}https\:\/\/mega\.nz\/file\/.{0,1000}greyware_tool_keywordmega.nzDirect file download links on Mega.nz - file sharing activity often abused by attackers for CollectionT1105 - T1114 - T1083TA0009N/AAkira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black BastaCollectionN/A11#filehostingservice #P2PN/A78N/AN/AN/AN/A47832
421*https://mega.nz/folder/*.{0,1000}https\:\/\/mega\.nz\/folder\/.{0,1000}greyware_tool_keywordmega.nzDirect folder sharing links on Mega.nz for accessing multiple files - file sharing activity often abused by attackers for CollectionT1105 - T1114 - T1083TA0009N/AAkira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black BastaCollectionN/A11#filehostingservice #P2PN/A78N/AN/AN/AN/A47833
422*https://privnote.com/*.{0,1000}https\:\/\/privnote\.com\/.{0,1000}greyware_tool_keywordprivnote.comtemporary notes service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAkira - Black BastaCollectionhttps://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Akira/20240620.json#L31C27-L31C4811#PastebinLikedownloading files url56504512025-04-19T17:43:15Z2023-05-02T16:17:48Z47878
423*https://put.io/default/magnet?url=*.{0,1000}https\:\/\/put\.io\/default\/magnet\?url\=.{0,1000}greyware_tool_keywordput.ioA storage and torrenting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AScattered Spider - RagnarLocker - MedusaCollectionhttps://put.i11#filehostingservice #P2PN/A1010N/AN/AN/AN/A47883
424*https://qaz.im/load/*.{0,1000}https\:\/\/qaz\.im\/load\/.{0,1000}greyware_tool_keywordqaz.imtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.im/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47890
425*https://qaz.im/zaq/*.{0,1000}https\:\/\/qaz\.im\/zaq\/.{0,1000}greyware_tool_keywordqaz.imtemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.im/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47891
426*https://qaz.is/load/*.{0,1000}https\:\/\/qaz\.is\/load\/.{0,1000}greyware_tool_keywordqaz.istemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.is/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47893
427*https://qaz.is/zaq/*.{0,1000}https\:\/\/qaz\.is\/zaq\/.{0,1000}greyware_tool_keywordqaz.istemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.is/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47894
428*https://qaz.su/load/*.{0,1000}https\:\/\/qaz\.su\/load\/.{0,1000}greyware_tool_keywordqaz.sutemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.su/11#filehostingservicedownloading files url1010N/AN/AN/AN/A47896
429*https://qaz.su/zaq/*.{0,1000}https\:\/\/qaz\.su\/zaq\/.{0,1000}greyware_tool_keywordqaz.sutemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLocker - Black BastaCollectionhttps://qaz.su/11#filehostingservicedownloading notes url1010N/AN/AN/AN/A47897
430*https://qu.ax/*.*https\:\/\/qu\.ax\/[^\s\n]+greyware_tool_keywordqu.axqu.ax is a quick and private file hosting service - abused by threat actorsT1560.001 - T1190 - T1102 - T1027.002TA0001 - TA0005 - TA0042N/AN/ACollectionhttps://qu[.]ax/11#filehostingserviceN/A910N/AN/AN/AN/A47898
431*https://rentry.co/*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}greyware_tool_keywordrentry.coaccessing a pastebinlike site - often abused by malwareT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A58N/AN/AN/AN/A47912
432*https://rentry.co/*/raw*.{0,1000}https\:\/\/rentry\.co\/.{0,1000}\/raw.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A47913
433*https://rentry.co/cdn-cgi/challenge-platform/*.{0,1000}https\:\/\/rentry\.co\/cdn\-cgi\/challenge\-platform\/.{0,1000}greyware_tool_keywordrentry.coraw format paste access attempt - abused by attackers to store malicious payloadsT1105 - T1114 - T1083TA0009N/AN/ACollectionN/A11#PastebinLikeN/A78N/AN/AN/AN/A47914
434*https://s3.filebin.net/filebin/*.{0,1000}https\:\/\/s3\.filebin\.net\/filebin\/.{0,1000}greyware_tool_keywordfilebin.netfile hosting platform abused by attackers to host malicious file - raw access and api availableT1119TA0009N/AN/ACollectionhttps://filebin.net11#filehostingserviceN/A88N/AN/AN/AN/A47917
435*https://send.exploit.in/api/download*.{0,1000}https\:\/\/send\.exploit\.in\/api\/download.{0,1000}greyware_tool_keywordsend.exploit.indownloading files - hosting service frequently exploited by attackers - should be blockedT1567 - T1071 - T1020 - T1005TA0010 - TA0009N/ALockBit - Hive - Black BastaCollectionN/A11#filehostingserviceN/A1010N/AN/AN/AN/A47921
436*https://share.riseup.net/2*.{0,1000}https\:\/\/share\.riseup\.net\/2.{0,1000}greyware_tool_keywordshare.riseup.nettemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AAvosLockerCollectionhttps://share.riseup.net11#filehostingservicedownloading files url1010N/AN/AN/AN/A47925
437*https://steamcommunity.com/profiles/*.{0,1000}https\:\/\/steamcommunity\.com\/profiles\/.{0,1000}greyware_tool_keywordsteamSteam profiles have been leveraged to host payload addresses for malware delivery - making them a potential threat vector in corporate environments. This tactic can serve as a valuable hunting tip for threat detection effortsT1102 - T1091 - T1204TA0001 - TA0009Lumma StealerN/ACollectionN/A01N/AN/A11N/AN/AN/AN/A47941
438*https://temp.sh/*/*.{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000}greyware_tool_keywordtemp.shInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ABlack BastaCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47955
439*https://tempsend.com/*.{0,1000}https\:\/\/tempsend\.com\/.{0,1000}greyware_tool_keywordtempsend.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/ACollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47957
440*https://termbin.com/test*.{0,1000}https\:\/\/termbin\.com\/test.{0,1000}greyware_tool_keywordtermbin.comaccessing paste raw contentT1119TA0009N/AN/ACollectiontermbin.com11N/AN/A88N/AN/AN/AN/A47959
441*https://textbin.net/raw/*.{0,1000}https\:\/\/textbin\.net\/raw\/.{0,1000}greyware_tool_keywordtextbin.nettextbin.net raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectiontextbin.net11#PastebinLikegreyware tool - risks of False positive !1010N/AN/AN/AN/A47960
442*https://tmpfiles.org/dl/*.exe*.{0,1000}https\:\/\/tmpfiles\.org\/dl\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordtmpfiles.orgdownload of an executable files from tmpfiles.org often used by ransomware groupsT1566.002 - T1192 - T1105TA0001 - TA0002N/AN/ACollectionN/A11#filehostingservicegreyware tool - risk of false positive !1010N/AN/AN/AN/A47963
443*https://transfer.sh/get/*/*.pdf*.{0,1000}https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.pdf.{0,1000}offensive_tool_keywordtransfer.shDownloading pdf from transfer.shT1105 - T1204 - T1071 - T1195TA0002 - TA0005 - TA0006N/ABlack BastaCollectionhttps://medium.com/checkmarx-security/python-obfuscation-traps-1acced94137511#filehostingserviceN/A108N/AN/AN/AN/A47968
444*https://transfer.sh/get/*/*.py*https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.py.{0,1000}offensive_tool_keywordtransfer.shDownloading python scripts from transfer.shT1105 - T1204 - T1071 - T1195TA0002 - TA0005 - TA0006N/ABlack BastaCollectionhttps://medium.com/checkmarx-security/python-obfuscation-traps-1acced94137511#filehostingserviceN/A108N/AN/AN/AN/A47969
445*https://transfert-my-files.com/files/*.{0,1000}https\:\/\/transfert\-my\-files\.com\/files\/.{0,1000}greyware_tool_keywordtransfert-my-files.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/AN/ACollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A47970
446*https://ufile.io/*.{0,1000}https\:\/\/ufile\.io\/.{0,1000}greyware_tool_keywordufile.iotemporary file hosting service - abused by attackers to share informations with their victimsT1105 - T1071TA0010 - TA0009N/AHiveCollectionhttps://ufile.io11N/Adownloading files url56N/AN/AN/AN/A47978
447*https://www.4shared.com/get/*.{0,1000}https\:\/\/www\.4shared\.com\/get\/.{0,1000}greyware_tool_keyword4shared.comDownloading a file from 4shared.comT1105 - T1071 - T1125TA0009N/ATurlaCollection4shared.com11#filehostingserviceN/A65N/AN/AN/AN/A47998
448*https://www.mediafire.com/api/*/folder/get_content.php*.{0,1000}https\:\/\/www\.mediafire\.com\/api\/.{0,1000}\/folder\/get_content\.php.{0,1000}greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1114 - T1083TA0009N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A48014
449*https://www.nirsoft.net/toolsdownload/*.{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}greyware_tool_keywordnirsoft toolsNirSoft is a legitimate software company that develops system utilities for Windows. Some of its tools can be used by malicious actors to recover passwords harvest sensitive information and conduct password attacks.T1003 - T1003.001 - T1003.002 - T1110 - T1566TA0002 - TA0003 - TA0004 - TA0006 - TA0007 - TA0008 - TA0011N/AN/ACollectionN/A11N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A48016
450*https://www.nirsoft.net/utils/webcamimagesave.zip*https\:\/\/www\.nirsoft\.net\/utils\/webcamimagesave\.zipoffensive_tool_keywordnirsoftdesigned to capture webcam imagesT1125 - T1056.004 - T1140TA0005 - TA0006N/AN/ACollectionhttps://medium.com/checkmarx-security/python-obfuscation-traps-1acced94137511N/AN/A108N/AN/AN/AN/A48021
451*https://www.premiumize.me/*.{0,1000}https\:\/\/www\.premiumize\.me\/.{0,1000}greyware_tool_keywordpremiumize.mehosting service abused by attackersT1583.003 - T1071 - T1102TA0010 - TA0005 - TA0009N/AN/ACollectionwww.premiumize.me11#filehostingservice #P2PN/A1010N/AN/AN/AN/A48022
452*https://www.sendspace.com/delete*.{0,1000}https\:\/\/www\.sendspace\.com\/delete.{0,1000}greyware_tool_keywordsendspace.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ADispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice SocietyCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A48023
453*https://www.sendspace.com/file/*.{0,1000}\shttps\:\/\/www\.sendspace\.com\/file\/.{0,1000}greyware_tool_keywordsendspace.comInteresting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victimsT1567 - T1022 - T1074 - T1105TA0011 - TA0009 - TA0010 - TA0008N/ADispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice SocietyCollectionhttps://twitter.com/mthcht/status/166095389762254438411#filehostingservicegreyware tool - risks of False positive !1010N/AN/AN/AN/A48024
454*https://www.telerik.com/download/fiddler/*.{0,1000}https\:\/\/www\.telerik\.com\/download\/fiddler\/.{0,1000}greyware_tool_keywordfiddlerfiddler - capture https requestsT1056 - T1040 - T1557TA0009 - TA00010N/AN/ACollectionhttps://www.telerik.com/11N/AN/A610N/AN/AN/AN/A48032
455*https://zerobin.net/?*.{0,1000}https\:\/\/zerobin\.net\/\?.{0,1000}greyware_tool_keywordzerobin.netaccessing paste raw contentT1119TA0009N/AN/ACollectionhttps://zerobin.net/11#PastebinLikeN/A88N/AN/AN/AN/A48041
456*IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/*.{0,1000}IEX\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(\"https\:\/\/raw\.githubusercontent\.com\/.{0,1000}greyware_tool_keywordpowershelldownload from github from memoryT1105 - T1059.001 - T1204TA0009 - TA0002N/AN/ACollectionN/A10N/AN/A610N/AN/AN/AN/A48209
457*IEX*nopaste.net*.{0,1000}IEX.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A48210
458*imaohw/nib/rsu/*.{0,1000}imaohw\/nib\/rsu\/.{0,1000}offensive_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0006 - TA0007N/ABlack BastaCollectionN/A10N/AN/AN/A10N/AN/AN/AN/A48237
459*InvokeReflectivePEInjection*.{0,1000}InvokeReflectivePEInjection.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z49412
460*Invoke-ReflectivePEInjection*.{0,1000}Invoke\-ReflectivePEInjection.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z49415
461*IWR*nopaste.net*.{0,1000}IWR.{0,1000}nopaste\.net.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A49983
462*kerberos::golden *.kirbi*.{0,1000}kerberos\:\:golden\s.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z50326
463*KidLogger-*.dmg*.{0,1000}KidLogger\-.{0,1000}\.dmg.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11#macosN/A1010N/AN/AN/AN/A50446
464*kidlogger.conf*.{0,1000}kidlogger\.conf.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A50447
465*Kidlogger.exe*.{0,1000}Kidlogger\.exe.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11N/AN/A1010N/AN/AN/AN/A50448
466*KidLogger.lnk*.{0,1000}KidLogger\.lnk.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A50449
467*KidLogger.net*.{0,1000}KidLogger\.net.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11N/AN/A1010N/AN/AN/AN/A50450
468*KidLogger.pif*.{0,1000}KidLogger\.pif.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A50451
469*KidLogger.url*.{0,1000}KidLogger\.url.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A50452
470*kidlogger_install*.{0,1000}kidlogger_install.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11N/AN/A1010N/AN/AN/AN/A50453
471*kidlogger_user.exe*.{0,1000}kidlogger_user\.exe.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html11N/AN/A1010N/AN/AN/AN/A50454
472*L3Vzci9iaW4vd2hvYW1p*.{0,1000}L3Vzci9iaW4vd2hvYW1p.{0,1000}offensive_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0006 - TA0007N/ABlack BastaCollectionN/A10N/AN/AN/A10N/AN/AN/AN/A50681
473*lanscan_arp.py*.{0,1000}lanscan_arp\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z50789
474*make shared dir for kidlogger ini files*.{0,1000}make\sshared\sdir\sfor\skidlogger\sini\sfiles.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A51565
475*MpCmdRun.exe -DownloadFile -url http://*.exe -path *.{0,1000}MpCmdRun\.exe\s\-DownloadFile\s\-url\shttp\:\/\/.{0,1000}\.exe\s\-path\s.{0,1000}greyware_tool_keywordMpCmdRunMpCmdRun LOLBAS exploitation observed used by threat actorsT1105TA0009 N/AN/ACollectionN/A10N/AN/A1010N/AN/AN/AN/A52307
476*mshta https://tinyurl.com/*.{0,1000}mshta\shttps\:\/\/tinyurl\.com\/.{0,1000}greyware_tool_keywordmshtadownloading from tinyurlT1204.002 - T1105 - T1071.001 - T1102.003TA0009 N/AN/ACollectionN/A10N/AN/A1010N/AN/AN/AN/A52402
477*mshta javascript:a=(GetObject("script:http*.sct*)).Exec();close();*.{0,1000}mshta\sjavascript\:a\=\(GetObject\(\"script\:http.{0,1000}\.sct.{0,1000}\)\)\.Exec\(\)\;close\(\)\;.{0,1000}greyware_tool_keywordmshtaInvoking a scriptlet file hosted remotelyT1218.005 - T1059.001 - T1105TA0002 - TA0009N/AN/ACollectionN/A10N/AN/A810N/AN/AN/AN/A52404
478*mshta.exe https://tinyurl.com/*.{0,1000}mshta\.exe\shttps\:\/\/tinyurl\.com\/.{0,1000}greyware_tool_keywordmshtadownloading from tinyurlT1204.002 - T1105 - T1071.001 - T1102.003TA0009 N/AN/ACollectionN/A10N/AN/A1010N/AN/AN/AN/A52407
479*mshta.exe javascript:a=(GetObject("script:http*.sct*)).Exec();close();*.{0,1000}mshta\.exe\sjavascript\:a\=\(GetObject\(\"script\:http.{0,1000}\.sct.{0,1000}\)\)\.Exec\(\)\;close\(\)\;.{0,1000}greyware_tool_keywordmshtaInvoking a scriptlet file hosted remotelyT1218.005 - T1059.001 - T1105TA0002 - TA0009N/AN/ACollectionN/A10N/AN/A810N/AN/AN/AN/A52408
480*New-VolumeShadowCopy -Volume C:\*.{0,1000}New\-VolumeShadowCopy\s\-Volume\sC\:\\.{0,1000}offensive_tool_keywordPowersploitPowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of filesT1003 - T1103 - T1213TA0006 - TA0009 - TA0010N/ADispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - TurlaCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A53314
481*nmap_port_scanner.py*.{0,1000}nmap_port_scanner\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z53478
482*nmap_port_scanner_ip_obj.py*.{0,1000}nmap_port_scanner_ip_obj\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z53479
483*nopaste.net*IWR*.{0,1000}nopaste\.net.{0,1000}IWR.{0,1000}greyware_tool_keywordnopaste.netnopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltrationT1567.002 - T1036.005 - T1102 - T1071.001TA0005 - TA0009 - TA0010N/AN/ACollectionhttps://www.shellhub.io/10#Pastebinlike #filehostingserviceN/A810N/AN/AN/AN/A53543
484*Nothing was logged into the temp workingKeyLog!*.{0,1000}Nothing\swas\slogged\sinto\sthe\stemp\sworkingKeyLog!.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z53575
485*objects.githubusercontent.com/github-production-release-asset-*.{0,1000}objects\.githubusercontent\.com\/github\-production\-release\-asset\-.{0,1000}greyware_tool_keywordgithubGithub executables download initiated - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A53821
486*package kidlogger*.{0,1000}package\skidlogger.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A54340
487*paste.ee/d/*.{0,1000}paste\.ee\/d\/.{0,1000}greyware_tool_keywordpaste.eefetching data from paste.eeT1041TA0009N/AN/ACollectionpaste.ee11#PastebinLikeN/A810N/AN/AN/AN/A54489
488*pastebin.com*/raw/* .{0,1000}pastebin\.com.{0,1000}\/raw\/.{0,1000}\sgreyware_tool_keywordpastebinpastebin raw access content - abused by malwares to retrieve payloadsT1119TA0009Redline StealerBlack BastaCollectionpastebin.com11#PastebinLikegreyware tool - risks of False positive !810N/AN/AN/AN/A54491
489*pastebin.com*/rw/*.{0,1000}pastebin\.com.{0,1000}\/rw\/.{0,1000}greyware_tool_keywordpastebinpastebin raw access content - abused by malwares to retrieve payloadsT1119TA0009Redline StealerBlack BastaCollectionpastebin.com11#PastebinLikegreyware tool - risks of False positive !810N/AN/AN/AN/A54492
490*pastebin.pl/view/raw/*.{0,1000}pastebin\.pl\/view\/raw\/.{0,1000}greyware_tool_keywordpastebin.placcessing paste raw contentT1119TA0009N/AN/ACollectionhttps://pastebin.pl/11#PastebinLikeN/A88N/AN/AN/AN/A54495
491*Payload-Generator/trix-back-gen.zip*.{0,1000}Payload\-Generator\/trix\-back\-gen\.zip.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters11N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z54549
492*pipx install graphspy*.{0,1000}pipx\sinstall\sgraphspy.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z54895
493*pipx upgrade graphspy*.{0,1000}pipx\supgrade\sgraphspy.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy10N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z54897
494*port_scanner_ip_obj.py*.{0,1000}port_scanner_ip_obj\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z55023
495*port_scanner_regex.py*.{0,1000}port_scanner_regex\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z55024
496*powershell.exe curl http://[0-9]{1,3}*.{0,1000}powershell.+curl\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000}greyware_tool_keywordpowershelldownloading from IP without domain nameT1105TA0009N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html10N/Aonly the regex part matters610N/AN/AN/AN/A55216
497*powershell.exe Invoke-WebRequest http://[0-9]{1,3}*.{0,1000}powershell\.exe\s+Invoke\-WebRequest\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000}greyware_tool_keywordpowershelldownloading from IP without domain nameT1105TA0009N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html10N/Aonly the regex part matters610N/AN/AN/AN/A55221
498*powershell.exe iwr http://[0-9]{1,3}*.{0,1000}powershell\.exe\s+iwr\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000}greyware_tool_keywordpowershelldownloading from IP without domain nameT1105TA0009N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html10N/Aonly the regex part matters610N/AN/AN/AN/A55222
499*powershell.exe -nop -c "start-job *Import-Module BitsTransfer*$env:temp*GetRandomFileName()*Start-BitsTransfer -Source 'http*Remove-Item*Receive-Job*powershell\.exe\s\-nop\s\-c\s\"start\-job\s.{0,1000}Import\-Module\sBitsTransfer.{0,1000}\$env\:temp.{0,1000}GetRandomFileName\(\).{0,1000}Start\-BitsTransfer\s\-Source\s\'http.{0,1000}Remove\-Item.{0,1000}Receive\-Job.{0,1000}offensive_tool_keywordpowershelldeployment of a payload through a PowerShell stager using bits to downloadT1197TA0009N/AN/ACollectionhttps://thedfirreport.com/2023/09/25/from-screenconnect-to-hive-ransomware-in-61-hours/10N/AN/A810N/AN/AN/AN/A55229
500*powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://[0-9]{1,3}*.{0,1000}powershell.+\s-nop\s-w\shidden\s-c\s\"IEX\s\(\(new\-object net\.webclient\)\.downloadstring\(\'http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000}greyware_tool_keywordpowershelldownloading from IP without domain nameT1105TA0009N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html10N/Aonly the regex part matters610N/AN/AN/AN/A55237
501*powershell.exe wget http://[0-9]{1,3}*.{0,1000}powershell\.exe\s+wget\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000}greyware_tool_keywordpowershelldownloading from IP without domain nameT1105TA0009N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html10N/Aonly the regex part matters610N/AN/AN/AN/A55241
502*PowerShell/Turla.T*.{0,1000}PowerShell\/Turla\.T.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z55247
503*pysnaffler -*.{0,1000}pysnaffler\s\-.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56038
504*pysnaffler 'smb2+kerberos+password:*.{0,1000}pysnaffler\s\'smb2\+kerberos\+password\:.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56039
505*pysnaffler 'smb2+ntlm-nt://*.{0,1000}pysnaffler\s\'smb2\+ntlm\-nt\:\/\/.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56040
506*pysnaffler 'smb2+ntlm-password://*.{0,1000}pysnaffler\s\'smb2\+ntlm\-password\:\/\/.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56041
507*pysnaffler.whatif:main*.{0,1000}pysnaffler\.whatif\:main.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56042
508*pysnaffler/_version.py*.{0,1000}pysnaffler\/_version\.py.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler10N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56043
509*pysnaffler-main*.{0,1000}pysnaffler\-main.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler11N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z56044
510*raw.githubusercontent.com*.7z*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.7z.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56304
511*raw.githubusercontent.com*.apk*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.apk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56305
512*raw.githubusercontent.com*.app*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.app.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56306
513*raw.githubusercontent.com*.as*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.as.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56307
514*raw.githubusercontent.com*.asc*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.asc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56308
515*raw.githubusercontent.com*.asp*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.asp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56309
516*raw.githubusercontent.com*.bash*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.bash.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11#linuxgreyware tool - risks of False positive !910N/AN/AN/AN/A56310
517*raw.githubusercontent.com*.bat*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.bat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56311
518*raw.githubusercontent.com*.beacon*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.beacon.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56312
519*raw.githubusercontent.com*.bin*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.bin.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56313
520*raw.githubusercontent.com*.bpl*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.bpl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56314
521*raw.githubusercontent.com*.c.{0,1000}raw\.githubusercontent\.com.{0,1000}\.cgreyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56315
522*raw.githubusercontent.com*.cer*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.cer.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56316
523*raw.githubusercontent.com*.cmd*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.cmd.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56317
524*raw.githubusercontent.com*.com*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.com.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56318
525*raw.githubusercontent.com*.cpp*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.cpp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56319
526*raw.githubusercontent.com*.crt*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.crt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56320
527*raw.githubusercontent.com*.cs*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.cs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56321
528*raw.githubusercontent.com*.csh*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.csh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56322
529*raw.githubusercontent.com*.dat*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.dat.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56323
530*raw.githubusercontent.com*.dll*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.dll.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56324
531*raw.githubusercontent.com*.docm*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.docm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56325
532*raw.githubusercontent.com*.dos*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.dos.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56326
533*raw.githubusercontent.com*.exe*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.exe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56327
534*raw.githubusercontent.com*.go*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.go.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56328
535*raw.githubusercontent.com*.gz*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.gz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56329
536*raw.githubusercontent.com*.hta*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.hta.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56330
537*raw.githubusercontent.com*.iso*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.iso.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56331
538*raw.githubusercontent.com*.jar*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.jar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56332
539*raw.githubusercontent.com*.js*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.js.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56333
540*raw.githubusercontent.com*.lnk*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.lnk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56334
541*raw.githubusercontent.com*.log*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.log.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56335
542*raw.githubusercontent.com*.mac*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.mac.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56336
543*raw.githubusercontent.com*.mam*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.mam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56337
544*raw.githubusercontent.com*.msi*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.msi.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56338
545*raw.githubusercontent.com*.msp*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.msp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56339
546*raw.githubusercontent.com*.nexe*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.nexe.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56340
547*raw.githubusercontent.com*.nim*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.nim.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56341
548*raw.githubusercontent.com*.otm*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.otm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56342
549*raw.githubusercontent.com*.out*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.out.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56343
550*raw.githubusercontent.com*.ova*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.ova.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56344
551*raw.githubusercontent.com*.pem*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pem.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56345
552*raw.githubusercontent.com*.pfx*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pfx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56346
553*raw.githubusercontent.com*.pl*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pl.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56347
554*raw.githubusercontent.com*.plx*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.plx.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56348
555*raw.githubusercontent.com*.pm*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56349
556*raw.githubusercontent.com*.ppk*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.ppk.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56350
557*raw.githubusercontent.com*.ps1*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.ps1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56351
558*raw.githubusercontent.com*.psm1*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.psm1.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56352
559*raw.githubusercontent.com*.pub*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pub.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56353
560*raw.githubusercontent.com*.py*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.py.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56354
561*raw.githubusercontent.com*.pyc*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pyc.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56355
562*raw.githubusercontent.com*.pyo*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.pyo.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56356
563*raw.githubusercontent.com*.rar*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.rar.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56357
564*raw.githubusercontent.com*.raw*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.raw.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56358
565*raw.githubusercontent.com*.reg*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.reg.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56359
566*raw.githubusercontent.com*.rgs*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.rgs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56360
567*raw.githubusercontent.com*.RGS*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.RGS.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56361
568*raw.githubusercontent.com*.run*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.run.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56362
569*raw.githubusercontent.com*.scpt*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.scpt.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56363
570*raw.githubusercontent.com*.script*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.script.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56364
571*raw.githubusercontent.com*.sct*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.sct.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56365
572*raw.githubusercontent.com*.sh*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.sh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56366
573*raw.githubusercontent.com*.ssh*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.ssh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56367
574*raw.githubusercontent.com*.sys*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.sys.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56368
575*raw.githubusercontent.com*.teamserver*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.teamserver.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56369
576*raw.githubusercontent.com*.temp*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.temp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56370
577*raw.githubusercontent.com*.tgz*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.tgz.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56371
578*raw.githubusercontent.com*.tmp*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.tmp.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56372
579*raw.githubusercontent.com*.vb*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.vb.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56373
580*raw.githubusercontent.com*.vbs*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.vbs.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56374
581*raw.githubusercontent.com*.vbscript*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.vbscript.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56375
582*raw.githubusercontent.com*.ws*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.ws.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56376
583*raw.githubusercontent.com*.wsf*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.wsf.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56377
584*raw.githubusercontent.com*.wsh*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.wsh.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56378
585*raw.githubusercontent.com*.X86*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.X86.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56379
586*raw.githubusercontent.com*.X86_64*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.X86_64.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56380
587*raw.githubusercontent.com*.xlam*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlam.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56381
588*raw.githubusercontent.com*.xlm*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56382
589*raw.githubusercontent.com*.xlsm*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlsm.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56383
590*raw.githubusercontent.com*.zip*.{0,1000}raw\.githubusercontent\.com.{0,1000}\.zip.{0,1000}greyware_tool_keywordgithubGithub raw access content - abused by malwares to retrieve payloadsT1119TA0009N/AN/ACollectionhttps://github.com/11N/Agreyware tool - risks of False positive !910N/AN/AN/AN/A56384
591*RedByte1337/GraphSpy*.{0,1000}RedByte1337\/GraphSpy.{0,1000}offensive_tool_keywordGraphSpyInitial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUIT1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656TA0001 - TA0006 - TA0003 - TA0005 - TA0008N/AN/ACollectionhttps://github.com/RedByte1337/GraphSpy11N/AN/A107680722025-04-15T21:07:15Z2024-02-07T19:47:15Z56544
592*reg save hklm\sam *.dat*.{0,1000}reg\ssave\shklm\\sam\s.{0,1000}\.dat.{0,1000}greyware_tool_keywordregsaves a copy of the registry hive hklm\sam to a .dat fileT1003.002 - T1564.001TA0006 - TA0010N/AVolt TyphoonCollectionhttps://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF10#registryN/A1010N/AN/AN/AN/A56835
593*reg save HKLM\SAM *c:*.{0,1000}reg\ssave\sHKLM\\SAM\s.{0,1000}c\:.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56836
594*reg save hklm\sam sam*.{0,1000}reg\ssave\shklm\\sam\ssam.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56838
595*reg save HKLM\SECURITY *.{0,1000}reg\ssave\sHKLM\\SECURITY\s.{0,1000}c\:.{0,1000}greyware_tool_keywordregsaves a copy of the registry hive hklm\security to a .dat fileT1005 - T1003.002TA0005 - TA0003N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a10#registryN/A1010N/AN/AN/AN/A56839
596*reg save hklm\system *.dat*.{0,1000}reg\ssave\shklm\\system\s.{0,1000}\.dat.{0,1000}greyware_tool_keywordregsaves a copy of the registry hive hklm\system to a .dat fileT1005 - T1003.002TA0005 - TA0003N/AVolt TyphoonCollectionhttps://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF10#registryN/A1010N/AN/AN/AN/A56840
597*reg save HKLM\SYSTEM *c:*.{0,1000}reg\ssave\sHKLM\\SYSTEM\s.{0,1000}c\:.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registrygreyware tool - risks of False positive !1010N/AN/AN/AN/A56841
598*reg save hklm\system system*.{0,1000}reg\ssave\shklm\\system\ssystem.{0,1000}greyware_tool_keywordregthe commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access.T1003.002TA0009N/ARancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registrygreyware tool - risks of False positive !1010N/AN/AN/AN/A56843
599*reg.exe save hklm\sam *.{0,1000}reg\.exe\ssave\shklm\\sam\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56862
600*reg.exe save hklm\security *.{0,1000}reg\.exe\ssave\shklm\\security\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56865
601*reg.exe save hklm\system *.{0,1000}reg\.exe\ssave\shklm\\system\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56868
602*reg.exe" save hklm\sam *.{0,1000}reg\.exe\"\ssave\shklm\\sam\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56875
603*reg.exe" save hklm\security *.{0,1000}reg\.exe\"\ssave\shklm\\security\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56876
604*reg.exe" save hklm\system *.{0,1000}reg\.exe\"\ssave\shklm\\system\s.{0,1000}greyware_tool_keywordregsaves a copy of the registry hiveT1003.002TA0009N/ADispossessor - Rancor - OilRig - Dragonfly - GALLIUM - TurlaCollectionN/A10#registryN/A1010N/AN/AN/AN/A56877
605*RegHiveBackup.exe*.{0,1000}RegHiveBackup\.exe.{0,1000}offensive_tool_keywordRegHiveBackupbackup the Registry files on your system into the specified folderT1012 - T1596 - T1003TA0006 - TA0009N/AN/ACollectionhttps://www.nirsoft.net/alpha/reghivebackup.zip11#registryN/A1010N/AN/AN/AN/A56887
606*rundll32.exe C:\windows\System32\comsvcs.dll MiniDump (Get-Process lsass).id*.{0,1000}rundll32\.exe\sC\:\\windows\\System32\\comsvcs\.dll\sMiniDump\s\(Get\-Process\slsass\)\.id.{0,1000}offensive_tool_keywordpowershellcredential dumping activityT1003.001TA0006N/AN/ACollectionhttps://www.trendmicro.com/en_us/research/22/g/analyzing-penetration-testing-tools-that-threat-actors-use-to-br.html10N/AN/A1010N/AN/AN/AN/A57707
607*scan_with_trufflehog(*.{0,1000}scan_with_trufflehog\(.{0,1000}offensive_tool_keywordwebtrufflehogBrowser extension that leverages TruffleHog to scan web traffic in real-time for exposed secretsT1552.001 - T1040 - T1036 - T1087TA0006 - TA0007 - TA0009N/AN/ACollectionhttps://github.com/c3l3si4n/webtrufflehog10#contentN/A72102102024-12-29T23:26:35Z2024-12-28T19:53:09Z58097
608*scp -P *system_info.txt*.{0,1000}scp\s\-P\s.{0,1000}system_info\.txt.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z58202
609*shehzade/peeping-tom*.{0,1000}shehzade\/peeping\-tom.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom11N/Akeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z59278
610*skelsec/pysnaffler*.{0,1000}skelsec\/pysnaffler.{0,1000}offensive_tool_keywordpysnafflerThis project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse.T1083 - T1087 - T1114 - T1518TA0007 - TA0009 - TA0010N/AN/ACollectionhttps://github.com/skelsec/pysnaffler11N/AN/A1019152025-03-15T13:46:34Z2023-11-17T21:52:40Z59583
611*smukx@proton.me*.{0,1000}smukx\@proton\.me.{0,1000}offensive_tool_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10#emailN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z59760
612*trickster0/EDR_Detector*.{0,1000}trickster0\/EDR_Detector.{0,1000}offensive_tool_keywordEDR_Detectordetect EDR agents on a machineT1518.001 - T1063TA0007 - TA0009N/AN/ACollectionhttps://github.com/trickster0/EDR_Detector11N/AN/A7193142021-11-05T08:10:05Z2019-08-24T20:50:09Z61566
613*Trojan.Keylogger.Win32*.{0,1000}Trojan\.Keylogger\.Win32.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z61577
614*uknowsec/keylogger*.{0,1000}uknowsec\/keylogger.{0,1000}offensive_tool_keywordkeyloggerKeyboard recordingT1056.001TA0006 - TA0009N/AN/ACollectionhttps://github.com/uknowsec/keylogger11N/AN/A92140352021-05-19T08:33:58Z2020-11-10T07:15:50Z61810
615*VolumeShadowCopyTools.ps1*.{0,1000}VolumeShadowCopyTools\.ps1.{0,1000}offensive_tool_keywordPowersploitPowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of filesT1003 - T1103 - T1213TA0006 - TA0009 - TA0010N/ADispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - TurlaCollectionhttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A1010N/AN/AN/AN/A62265
616*Volumiser.exe --image*.{0,1000}Volumiser\.exe\s\-\-image.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z62267
617*Volumiser\DiscUtils.Ebs\EbsMappedStream*.{0,1000}Volumiser\\DiscUtils\.Ebs\\EbsMappedStream.{0,1000}offensive_tool_keywordVolumiserVolumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats.T1560.001 - T1059 - T1114 - T1005TA0005 - TA0009N/AN/ACollectionhttps://github.com/CCob/Volumiser10N/AN/A74379422025-04-22T15:47:53Z2022-11-08T21:38:56Z62268
618*vssadmin create shadow /for=C:*.{0,1000}vssadmin\screate\sshadow\s\/for\=C\:.{0,1000}greyware_tool_keywordvssadminthe command is used to create a new Volume Shadow Copy for a specific volume which can be utilized by an attacker to collect data from the local systemT1005TA0009N/AN/ACollectionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A62281
619*vssadmin.exe Create Shadow /for=*.{0,1000}vssadmin\.exe\screate\sshadow\s\/for\=.{0,1000}greyware_tool_keywordvssadminthe command is used to create a new Volume Shadow Copy for a specific volume which can be utilized by an attacker to collect data from the local systemT1005TA0009N/AN/ACollectionN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A62292
620*W32/KeyLogger.PMU!tr.spy*.{0,1000}W32\/KeyLogger\.PMU!tr\.spy.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62334
621*whoami.exe* /groups*.{0,1000}whoami\.exe.{0,1000}\s\/groups.{0,1000}greyware_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0007N/ABlack BastaCollectionhttps://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.yaml10N/Agreyware tool - risks of False positive !8101046629042025-04-21T13:09:54Z2017-10-11T17:23:32Z62573
622*wifi_dos_own.py*.{0,1000}wifi_dos_own\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z62583
623*wifi_dos3.py*.{0,1000}wifi_dos3\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z62584
624*Win32/KidLogger*.{0,1000}Win32\/KidLogger.{0,1000}signature_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10N/AN/A1010N/AN/AN/AN/A62636
625*Win32/Spy.KeyLogger.PMU*.{0,1000}Win32\/Spy\.KeyLogger\.PMU.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62642
626*Win32/Turla.BZ*.{0,1000}Win32\/Turla\.BZ.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62644
627*Win64/Turla.BQ*.{0,1000}Win64\/Turla\.BQ.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62668
628*Win64/Turla.BR*.{0,1000}Win64\/Turla\.BR.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62669
629*Win64/Turla.BS*.{0,1000}Win64\/Turla\.BS.{0,1000}signature_keywordPowershell-Scripts-for-Hackers-and-PentestersT1059.001 - T1119 - T1027 - T1016 - T1056.001TA0002 - TA0009 - TA0005 - TA0007 - TA0010N/AN/ACollectionhttps://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters10N/AN/A105415492025-02-23T09:05:44Z2023-02-27T14:27:32Z62670
630*Windows keyboard hook installed & log exfiltration timer started*.{0,1000}Windows\skeyboard\shook\sinstalled\s\&\slog\sexfiltration\stimer\sstarted.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z62706
631*window-state@safejka.eu*.{0,1000}window\-state\@safejka\.eu.{0,1000}offensive_tool_keywordkigloggermalware parental control software - keyloggerT1056.001 - T1113 - T1056.004TA0006 - TA0009N/AN/ACollectionhttps://kidlogger.net/download.html10#emailN/A1010N/AN/AN/AN/A62772
632*wmic.exe process call create *cmd /c *.{0,1000}wmic\.exe\sprocess\scall\screate\s.{0,1000}cmd\s\/c\s.{0,1000}greyware_tool_keywordwmiccall cmd.exe with wmicT1047 - T1059TA0002 - TA0009N/AMAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEARCollectionN/A10N/Agreyware tool - risks of False positive !510N/AN/AN/AN/A62956
633*workingKeyLog has been pushed to key log file!*.{0,1000}workingKeyLog\shas\sbeen\spushed\sto\skey\slog\sfile!.{0,1000}offensive_tool_keywordpeeping-tomRemote keylogger for Windows written in C++T1056.001 - T1123 - T1129 - T1113TA0006 - TA0008 - TA0009N/ADispossessorCollectionhttps://github.com/shehzade/peeping-tom10#contentkeylogger101302022-07-24T09:31:59Z2022-04-15T14:16:41Z63043
634*www.mediafire.com/file/*.{0,1000}www\.mediafire\.com\/file\/.{0,1000}greyware_tool_keywordmediafiredownloading from mediafireT1105 - T1114 - T1083TA0009N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A63155
635*www.mediafire.com/file/*.rar/file*.{0,1000}www\.mediafire\.com\/file\/.{0,1000}\.rar\/file.{0,1000}greyware_tool_keywordmediafiredownloading from mediafire - rar archiveT1105 - T1083 - T1560TA0009 N/ABlack BastaCollectionN/A11#filehostingserviceN/A78N/AN/AN/AN/A63156
636*yeelight_discover.py*.{0,1000}yeelight_discover\.py.{0,1000}offensive_tool_keywordred-python-scriptsrandom networking exploitation scirptsT1190 - T1046 - T1065TA0001 - TA0007N/AN/ACollectionhttps://github.com/davidbombal/red-python-scripts10N/AN/A810209815992024-10-22T13:31:06Z2021-01-07T16:11:52Z63350
637*pentest-tools.com*.{0,1000}pentest\-tools\.com.{0,1000}offensive_tool_keywordpentest-toolscloud-based offensive security platform offering a wide range of automated penetration testing utilitiesT1595.002 - T1046 - T1083 - T1059 - T1190 - T1203TA0007 - TA0001 - TA0002N/AN/ACollectionpentest-tools.com11N/AN/A79N/AN/AN/AN/A63729
638*swisskyrepo.github.io*.{0,1000}swisskyrepo\.github\.io.{0,1000}offensive_tool_keywordpentest-toolscloud-based offensive security platform offering a wide range of automated penetration testing utilitiesT1595.002 - T1046 - T1083 - T1059 - T1190 - T1203TA0007 - TA0001 - TA0002N/AN/ACollectionN/A11N/AN/A79N/AN/AN/AN/A63730