mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
263 KiB
263 KiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * /c start /min powershell -noprofile -w H -c *irw* | .{0,1000}\s\/c\sstart\s\/min\spowershell\s\-noprofile\s\-w\sH\s\-c\s.{0,1000}irw.{0,1000} | greyware_tool_keyword | powershell | Suspicious PowerShell execution behavior often observed in FakeCaptcha phishing attempts | T1059.001 - T1027 - T1564.003 | TA0005 - TA0002 - TA0009 | N/A | N/A | Collection | https://x.com/malware_traffic/status/1884476331821326816/photo/2 | 1 | 0 | N/A | N/A | 7 | 6 | N/A | N/A | N/A | N/A | 45 |
| 3 | * all_in_one_enum.ps1* | .{0,1000}\sall_in_one_enum\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 258 | |
| 4 | * CarSeat.py * | .{0,1000}\sCarSeat\.py\s.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | N/A | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 546 |
| 5 | * dll-installer.ps1* | .{0,1000}\sdll\-installer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 872 | |
| 6 | * GraphSpy.py* | .{0,1000}\sGraphSpy\.py.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 1381 |
| 7 | * Invoke-WebRequest -Uri http://download.anydesk.com/AnyDesk.exe* | .{0,1000}\sInvoke\-WebRequest\s\-Uri\shttp\:\/\/download\.anydesk\.com\/AnyDesk\.exe.{0,1000} | greyware_tool_keyword | anydesk | command line used with anydesk in the notes of the Dispossessor ransomware group | T1486 - T1490 - T1059 - T1213 - T1078 | TA0040 - TA0043 - TA0001 - TA0009 | N/A | Dispossessor | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1753 |
| 8 | * process call create *cmd.exe /c powershell.exe -nop -w hidden -c *IEX ((new-object net.webclient).downloadstring('https://* | .{0,1000}\sprocess\scall\screate\s.{0,1000}cmd\.exe\s\/c\spowershell\.exe\s\-nop\s\-w\shidden\s\-c\s.{0,1000}IEX\s\(\(new\-object\snet\.webclient\)\.downloadstring\(\'https\:\/\/.{0,1000} | greyware_tool_keyword | wmic | Threat Actors ran the following command to download and execute a PowerShell payload | T1059.001 - T1059.003 - T1569.002 - T1021.006 | TA0002 - TA0005 | N/A | MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR - Dispossessor | Collection | https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2676 |
| 9 | * SendScreenshotToTelegram* | .{0,1000}\sSendScreenshotToTelegram.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 3037 | |
| 10 | * snaffler.py * | .{0,1000}\ssnaffler\.py\s.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 3271 |
| 11 | * Volumiser.exe * | .{0,1000}\sVolumiser\.exe\s.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 3678 |
| 12 | * -W Hidden -command *https://*Invoke-WebRequest*; iex $* | .{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}https\:\/\/.{0,1000}Invoke\-WebRequest.{0,1000}\;\siex\s\$.{0,1000} | greyware_tool_keyword | powershell | A PowerShell process downloaded and launched a remote file | T1059.001 - T1105 - T1203 | TA0001 - TA0002 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 3685 |
| 13 | * -W Hidden -command *Invoke-WebRequest*https://*; iex $* | .{0,1000}\s\-W\sHidden\s\-command\s.{0,1000}Invoke\-WebRequest.{0,1000}https\:\/\/.{0,1000}\;\siex\s\$.{0,1000} | greyware_tool_keyword | powershell | A PowerShell process downloaded and launched a remote file | T1059.001 - T1105 - T1203 | TA0001 - TA0002 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 3686 |
| 14 | * -w hidden -ep bypass -nop -Command "iex ((New-Object System.Net.WebClient).DownloadString(* | .{0,1000}\s\-w\shidden\s\-ep\sbypass\s\-nop\s\-Command\s\"iex\s\(\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(.{0,1000} | greyware_tool_keyword | powershell | suspicious powershell command often used in recaptcha phishing campaign (run dialog) | T1086 - T1105 - T1218.003 - T1569.002 | TA0002 - TA0009 | Lumma Stealer | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3687 |
| 15 | * win-key-killer.ps1* | .{0,1000}\swin\-key\-killer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 3726 | |
| 16 | *"HEHE YOU HAVE BEEN PWENED"* | .{0,1000}\"HEHE\sYOU\sHAVE\sBEEN\sPWENED\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 3844 | |
| 17 | *#CODED BY SMUKX* | .{0,1000}\#CODED\sBY\sSMUKX.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 3926 | |
| 18 | *$env:TEMP\winkeykey.txt* | .{0,1000}\$env\:TEMP\\winkeykey\.txt.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 3964 | |
| 19 | *./logger.sh * &> /dev/null && exit* | .{0,1000}\.\/logger\.sh\s.{0,1000}\s\&\>\s\/dev\/null\s\&\&\sexit.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 0 | #linux | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 4164 |
| 20 | *./snaffler_downloads* | .{0,1000}\.\/snaffler_downloads.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | #linux | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 4207 |
| 21 | */.gspy/databases/* | .{0,1000}\/\.gspy\/databases\/.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #linux | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 5016 |
| 22 | */.local/bin/graphspy* | .{0,1000}\/\.local\/bin\/graphspy.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #linux | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 5019 |
| 23 | */all_in_one_enum.ps1* | .{0,1000}\/all_in_one_enum\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 5279 | |
| 24 | */bin/kidlogger* | .{0,1000}\/bin\/kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5634 |
| 25 | */Carseat.git* | .{0,1000}\/Carseat\.git.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 1 | N/A | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 5955 |
| 26 | */CarSeat.py -* | .{0,1000}\/CarSeat\.py\s\-.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | N/A | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 5956 |
| 27 | */CCob/Volumiser* | .{0,1000}\/CCob\/Volumiser.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 1 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 5965 |
| 28 | */com.webtrufflehog.json* | .{0,1000}\/com\.webtrufflehog\.json.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 6154 |
| 29 | */dll-installer.ps1* | .{0,1000}\/dll\-installer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 6642 | |
| 30 | */download*mediafire.com/ | .{0,1000}\/download.{0,1000}mediafire\.com\/ | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1083 - T1560 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 6750 |
| 31 | */download/fiddler/fiddler-everywhere-windows* | .{0,1000}\/download\/fiddler\/fiddler\-everywhere\-windows.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 6751 |
| 32 | */EDR_Detector.git* | .{0,1000}\/EDR_Detector\.git.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 6888 |
| 33 | */EDR_Detector.rs* | .{0,1000}\/EDR_Detector\.rs.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 6889 |
| 34 | */etc/kidlogger* | .{0,1000}\/etc\/kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7008 |
| 35 | */Fiddler Everywhere *.*.*.exe* | .{0,1000}\/Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 7190 |
| 36 | */github.com*.exe?raw=true* | .{0,1000}\/github\.com.{0,1000}\.exe\?raw\=true.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7414 |
| 37 | */github.com/*/archive/refs/tags/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/archive\/refs\/tags\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7415 |
| 38 | */github.com/*/raw/main/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7416 |
| 39 | */github.com/*/raw/main/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7417 |
| 40 | */github.com/*/raw/main/*.app* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.app.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7418 |
| 41 | */github.com/*/raw/main/*.as* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.as.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7419 |
| 42 | */github.com/*/raw/main/*.asc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7420 |
| 43 | */github.com/*/raw/main/*.asp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.asp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7421 |
| 44 | */github.com/*/raw/main/*.bash* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bash.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | #linux | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7422 |
| 45 | */github.com/*/raw/main/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7423 |
| 46 | */github.com/*/raw/main/*.beacon* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.beacon.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7424 |
| 47 | */github.com/*/raw/main/*.bin* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bin.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7425 |
| 48 | */github.com/*/raw/main/*.bpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.bpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7426 |
| 49 | */github.com/*/raw/main/*.c* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.c.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7427 |
| 50 | */github.com/*/raw/main/*.cer* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cer.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7428 |
| 51 | */github.com/*/raw/main/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7429 |
| 52 | */github.com/*/raw/main/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7430 |
| 53 | */github.com/*/raw/main/*.cpp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cpp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7431 |
| 54 | */github.com/*/raw/main/*.crt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.crt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7432 |
| 55 | */github.com/*/raw/main/*.cs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.cs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7433 |
| 56 | */github.com/*/raw/main/*.csh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.csh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7434 |
| 57 | */github.com/*/raw/main/*.dat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7435 |
| 58 | */github.com/*/raw/main/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7436 |
| 59 | */github.com/*/raw/main/*.docm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.docm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7437 |
| 60 | */github.com/*/raw/main/*.dos* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.dos.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7438 |
| 61 | */github.com/*/raw/main/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7439 |
| 62 | */github.com/*/raw/main/*.go* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.go.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7440 |
| 63 | */github.com/*/raw/main/*.gz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.gz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7441 |
| 64 | */github.com/*/raw/main/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7442 |
| 65 | */github.com/*/raw/main/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7443 |
| 66 | */github.com/*/raw/main/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7444 |
| 67 | */github.com/*/raw/main/*.js* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.js.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7445 |
| 68 | */github.com/*/raw/main/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7446 |
| 69 | */github.com/*/raw/main/*.log* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.log.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7447 |
| 70 | */github.com/*/raw/main/*.mac* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mac.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7448 |
| 71 | */github.com/*/raw/main/*.mam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.mam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7449 |
| 72 | */github.com/*/raw/main/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7450 |
| 73 | */github.com/*/raw/main/*.msp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.msp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7451 |
| 74 | */github.com/*/raw/main/*.nexe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nexe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7452 |
| 75 | */github.com/*/raw/main/*.nim* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.nim.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7453 |
| 76 | */github.com/*/raw/main/*.otm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.otm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7454 |
| 77 | */github.com/*/raw/main/*.out* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.out.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7455 |
| 78 | */github.com/*/raw/main/*.ova* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ova.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7456 |
| 79 | */github.com/*/raw/main/*.pem* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pem.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7457 |
| 80 | */github.com/*/raw/main/*.pfx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pfx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7458 |
| 81 | */github.com/*/raw/main/*.pl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7459 |
| 82 | */github.com/*/raw/main/*.plx* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.plx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7460 |
| 83 | */github.com/*/raw/main/*.pm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7461 |
| 84 | */github.com/*/raw/main/*.ppk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ppk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7462 |
| 85 | */github.com/*/raw/main/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7463 |
| 86 | */github.com/*/raw/main/*.psm1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.psm1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7464 |
| 87 | */github.com/*/raw/main/*.pub* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pub.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7465 |
| 88 | */github.com/*/raw/main/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7466 |
| 89 | */github.com/*/raw/main/*.pyc* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7467 |
| 90 | */github.com/*/raw/main/*.pyo* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.pyo.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7468 |
| 91 | */github.com/*/raw/main/*.rar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7469 |
| 92 | */github.com/*/raw/main/*.raw* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.raw.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7470 |
| 93 | */github.com/*/raw/main/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7471 |
| 94 | */github.com/*/raw/main/*.rgs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.rgs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7472 |
| 95 | */github.com/*/raw/main/*.RGS* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.RGS.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7473 |
| 96 | */github.com/*/raw/main/*.run* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.run.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7474 |
| 97 | */github.com/*/raw/main/*.scpt* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.scpt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7475 |
| 98 | */github.com/*/raw/main/*.script* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.script.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7476 |
| 99 | */github.com/*/raw/main/*.sct* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sct.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7477 |
| 100 | */github.com/*/raw/main/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7478 |
| 101 | */github.com/*/raw/main/*.ssh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ssh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7479 |
| 102 | */github.com/*/raw/main/*.sys* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.sys.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7480 |
| 103 | */github.com/*/raw/main/*.teamserver* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.teamserver.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7481 |
| 104 | */github.com/*/raw/main/*.temp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.temp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7482 |
| 105 | */github.com/*/raw/main/*.tgz* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tgz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7483 |
| 106 | */github.com/*/raw/main/*.tmp* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.tmp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7484 |
| 107 | */github.com/*/raw/main/*.vb* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vb.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7485 |
| 108 | */github.com/*/raw/main/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7486 |
| 109 | */github.com/*/raw/main/*.vbscript* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.vbscript.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7487 |
| 110 | */github.com/*/raw/main/*.ws* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.ws.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7488 |
| 111 | */github.com/*/raw/main/*.wsf* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsf.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7489 |
| 112 | */github.com/*/raw/main/*.wsh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.wsh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7490 |
| 113 | */github.com/*/raw/main/*.X86* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7491 |
| 114 | */github.com/*/raw/main/*.X86_64* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.X86_64.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7492 |
| 115 | */github.com/*/raw/main/*.xlam* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7493 |
| 116 | */github.com/*/raw/main/*.xlm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7494 |
| 117 | */github.com/*/raw/main/*.xlsm* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.xlsm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7495 |
| 118 | */github.com/*/raw/main/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/main\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7496 |
| 119 | */github.com/*/raw/refs/heads/*.7z* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7497 |
| 120 | */github.com/*/raw/refs/heads/*.apk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7498 |
| 121 | */github.com/*/raw/refs/heads/*.bat* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7499 |
| 122 | */github.com/*/raw/refs/heads/*.cmd* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7500 |
| 123 | */github.com/*/raw/refs/heads/*.com* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7501 |
| 124 | */github.com/*/raw/refs/heads/*.cpl* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.cpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7502 |
| 125 | */github.com/*/raw/refs/heads/*.dll* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7503 |
| 126 | */github.com/*/raw/refs/heads/*.exe* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7504 |
| 127 | */github.com/*/raw/refs/heads/*.hta* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7505 |
| 128 | */github.com/*/raw/refs/heads/*.iso* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7506 |
| 129 | */github.com/*/raw/refs/heads/*.jar* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7507 |
| 130 | */github.com/*/raw/refs/heads/*.lnk* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7508 |
| 131 | */github.com/*/raw/refs/heads/*.msi* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7509 |
| 132 | */github.com/*/raw/refs/heads/*.pif* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.pif.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7510 |
| 133 | */github.com/*/raw/refs/heads/*.ps1* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7511 |
| 134 | */github.com/*/raw/refs/heads/*.py* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7512 |
| 135 | */github.com/*/raw/refs/heads/*.reg* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7513 |
| 136 | */github.com/*/raw/refs/heads/*.scr* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.scr.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7514 |
| 137 | */github.com/*/raw/refs/heads/*.sh* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7515 |
| 138 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7516 |
| 139 | */github.com/*/raw/refs/heads/*.vbs* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7517 |
| 140 | */github.com/*/raw/refs/heads/*.zip* | .{0,1000}\/github\.com\/.{0,1000}\/raw\/refs\/heads\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 7518 |
| 141 | */GraphSpy.git* | .{0,1000}\/GraphSpy\.git.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 1 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 7622 |
| 142 | */GraphSpy.py* | .{0,1000}\/GraphSpy\.py.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 1 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 7623 |
| 143 | */keylog.exe* | .{0,1000}\/keylog\.exe.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 8343 | |
| 144 | */keylogger.exe* | .{0,1000}\/keylogger\.exe.{0,1000} | offensive_tool_keyword | keylogger | Keyboard recording | T1056.001 | TA0006 - TA0009 | N/A | N/A | Collection | https://github.com/uknowsec/keylogger | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 35 | 2021-05-19T08:33:58Z | 2020-11-10T07:15:50Z | 8349 |
| 145 | */keylogger.git* | .{0,1000}\/keylogger\.git.{0,1000} | offensive_tool_keyword | keylogger | Keyboard recording | T1056.001 | TA0006 - TA0009 | N/A | N/A | Collection | https://github.com/uknowsec/keylogger | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 35 | 2021-05-19T08:33:58Z | 2020-11-10T07:15:50Z | 8351 |
| 146 | */KidLogger.app/* | .{0,1000}\/KidLogger\.app\/.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8355 |
| 147 | */kidlogger.desktop* | .{0,1000}\/kidlogger\.desktop.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8356 |
| 148 | */master/windows/klog_main.cpp* | .{0,1000}\/master\/windows\/klog_main\.cpp.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 8728 | |
| 149 | */opt/gspy_log.txt* | .{0,1000}\/opt\/gspy_log\.txt.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #linux #logfile | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 9412 |
| 150 | */peeping-client.exe* | .{0,1000}\/peeping\-client\.exe.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 1 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 9592 |
| 151 | */peeping-tom.app* | .{0,1000}\/peeping\-tom\.app.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 1 | #macos | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 9593 |
| 152 | */peeping-tom.exe* | .{0,1000}\/peeping\-tom\.exe.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 1 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 9594 |
| 153 | */peeping-tom.git* | .{0,1000}\/peeping\-tom\.git.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 1 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 9595 |
| 154 | */Powershell-Scripts-for-Hackers-and-Pentesters* | .{0,1000}\/Powershell\-Scripts\-for\-Hackers\-and\-Pentesters.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 9826 | |
| 155 | */pypi.org/project/GraphSpy* | .{0,1000}\/pypi\.org\/project\/GraphSpy.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 1 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 10086 |
| 156 | */pysnaffler.git* | .{0,1000}\/pysnaffler\.git.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 1 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 10097 |
| 157 | */reghivebackup.zip* | .{0,1000}\/reghivebackup\.zip.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 1 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 10321 |
| 158 | */snaffler.py* | .{0,1000}\/snaffler\.py.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 1 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 11454 |
| 159 | */srv/kidlogger* | .{0,1000}\/srv\/kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 11602 |
| 160 | */usr/share/kidlogger* | .{0,1000}\/usr\/share\/kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12376 |
| 161 | */Volumiser.exe* | .{0,1000}\/Volumiser\.exe.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 1 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 12478 |
| 162 | */Volumiser.git* | .{0,1000}\/Volumiser\.git.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 1 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 12479 |
| 163 | */Volumiser-maser.zip* | .{0,1000}\/Volumiser\-maser\.zip.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 1 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 12480 |
| 164 | */webtrufflehog.git* | .{0,1000}\/webtrufflehog\.git.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 1 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 12552 |
| 165 | */webtrufflehog.log* | .{0,1000}\/webtrufflehog\.log.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 12553 |
| 166 | */win-key-killer.ps1* | .{0,1000}\/win\-key\-killer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 12621 | |
| 167 | *[!] Please save this key as it will be required to decrypt the keylogs from the target!* | .{0,1000}\[!\]\sPlease\ssave\sthis\skey\sas\sit\swill\sbe\srequired\sto\sdecrypt\sthe\skeylogs\sfrom\sthe\starget!.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 12950 |
| 168 | *[+] Keylog recieved, data written to keylog.txt!* | .{0,1000}\[\+\]\sKeylog\srecieved,\sdata\swritten\sto\skeylog\.txt!.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 13207 |
| 169 | *[Ngrok Tunnel URL* | .{0,1000}\[Ngrok\sTunnel\sURL.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 13492 |
| 170 | *\all_in_one_enum.ps1* | .{0,1000}\\all_in_one_enum\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 13901 | |
| 171 | *\dll-installer.ps1* | .{0,1000}\\dll\-installer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 14982 | |
| 172 | *\EDR_Detector.rs* | .{0,1000}\\EDR_Detector\.rs.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 0 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 15221 |
| 173 | *\Fiddler Everywhere *.*.*.exe* | .{0,1000}\\Fiddler\sEverywhere\s.{0,1000}\..{0,1000}\..{0,1000}\.exe.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 0 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 15425 |
| 174 | *\GraphSpy.py* | .{0,1000}\\GraphSpy\.py.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 15721 |
| 175 | *\keylog.cpp* | .{0,1000}\\keylog\.cpp.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 16121 | |
| 176 | *\keylog.exe* | .{0,1000}\\keylog\.exe.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 16122 | |
| 177 | *\keylogger.exe* | .{0,1000}\\keylogger\.exe.{0,1000} | offensive_tool_keyword | keylogger | Keyboard recording | T1056.001 | TA0006 - TA0009 | N/A | N/A | Collection | https://github.com/uknowsec/keylogger | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 35 | 2021-05-19T08:33:58Z | 2020-11-10T07:15:50Z | 16127 |
| 178 | *\keylogger.txt* | .{0,1000}\\keylogger\.txt.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 16130 | |
| 179 | *\KidLogger\* | .{0,1000}\\KidLogger\\.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 16133 |
| 180 | *\KidLogger_is1* | .{0,1000}\\KidLogger_is1.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 16134 |
| 181 | *\peeping-client.exe* | .{0,1000}\\peeping\-client\.exe.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 17181 |
| 182 | *\peeping-tom.exe* | .{0,1000}\\peeping\-tom\.exe.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 17182 |
| 183 | *\peeping-tom-main* | .{0,1000}\\peeping\-tom\-main.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 17183 |
| 184 | *\Powershell-Scripts-for-Hackers-and-Pentesters* | .{0,1000}\\Powershell\-Scripts\-for\-Hackers\-and\-Pentesters.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 17388 | |
| 185 | *\Program Files (x86)\KidLogger* | .{0,1000}\\Program\sFiles\s\(x86\)\\KidLogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17501 |
| 186 | *\pysnaffler\pysnaffler\* | .{0,1000}\\pysnaffler\\pysnaffler\\.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 17694 |
| 187 | *\reg.exe* save HKLM* | .{0,1000}\\reg\.exe.{0,1000}\ssave\sHKLM.{0,1000} | greyware_tool_keyword | reg | T1003.002 - T1564.001 | TA0006 - TA0010 | N/A | N/A | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17882 | |
| 188 | *\RegHiveBackup.cfg* | .{0,1000}\\RegHiveBackup\.cfg.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17885 |
| 189 | *\reghivebackup.zip* | .{0,1000}\\reghivebackup\.zip.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 17886 |
| 190 | *\Root\InventoryApplicationFile\reghivebackup* | .{0,1000}\\Root\\InventoryApplicationFile\\reghivebackup.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 18096 |
| 191 | *\snaffler.py* | .{0,1000}\\snaffler\.py.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 18921 |
| 192 | *\Software\Kidlogger* | .{0,1000}\\Software\\Kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 18957 |
| 193 | *\toms-server\keylog.txt* | .{0,1000}\\toms\-server\\keylog\.txt.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 19388 |
| 194 | *\trix-back-gen.zip* | .{0,1000}\\trix\-back\-gen\.zip.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 19424 | |
| 195 | *\Volumiser.exe* | .{0,1000}\\Volumiser\.exe.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 19631 |
| 196 | *\Volumiser.sln* | .{0,1000}\\Volumiser\.sln.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 19632 |
| 197 | *\Volumiser\Program.cs* | .{0,1000}\\Volumiser\\Program\.cs.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 19633 |
| 198 | *\webtrufflehog.log* | .{0,1000}\\webtrufflehog\.log.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 19689 |
| 199 | *\webtrufflehog-main* | .{0,1000}\\webtrufflehog\-main.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 19690 |
| 200 | *\Windows\Temp\sam.save* | .{0,1000}\\Windows\\Temp\\sam\.save.{0,1000} | greyware_tool_keyword | reg | a copy of the registry hive | T1003.002 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 19754 |
| 201 | *\win-key-killer.ps1* | .{0,1000}\\win\-key\-killer\.ps1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 19779 | |
| 202 | *\WOW6432Node\Kidlogger* | .{0,1000}\\WOW6432Node\\Kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #registry | registry | 10 | 10 | N/A | N/A | N/A | N/A | 19859 |
| 203 | *\x2f\x75\x73\x72\x2f\x62\x69\x6e\x2f\x77\x68\x6f\x61\x6d\x69* | .{0,1000}\\x2f\\x75\\x73\\x72\\x2f\\x62\\x69\\x6e\\x2f\\x77\\x68\\x6f\\x61\\x6d\\x69.{0,1000} | offensive_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0006 - TA0007 | N/A | Black Basta | Collection | N/A | 1 | 0 | N/A | N/A | N/A | 10 | N/A | N/A | N/A | N/A | 19884 |
| 204 | *] Starting GraphSpy. Open in your browser by going to the url displayed below.* | .{0,1000}\]\sStarting\sGraphSpy\.\sOpen\sin\syour\sbrowser\sby\sgoing\sto\sthe\surl\sdisplayed\sbelow\..{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #content | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 20076 |
| 205 | *>Disk to VHD converter<* | .{0,1000}\>Disk\sto\sVHD\sconverter\<.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | #description | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 20378 |
| 206 | *>Disk2vhd<* | .{0,1000}\>Disk2vhd\<.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | #productname | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 20379 |
| 207 | *>RegHiveBackup<* | .{0,1000}\>RegHiveBackup\<.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 0 | #productname | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 20495 |
| 208 | *09b0fe289efa8c6364964bddedb339a7d43b0eaae912ef4c3f357325c6c55b61* | .{0,1000}09b0fe289efa8c6364964bddedb339a7d43b0eaae912ef4c3f357325c6c55b61.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 21361 |
| 209 | *0aa81384c29ae395069a9d6bf226f1345c7909cdc7181c2c4f1c9015268e940d* | .{0,1000}0aa81384c29ae395069a9d6bf226f1345c7909cdc7181c2c4f1c9015268e940d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 21419 |
| 210 | *0bin - encrypted pastebin* | .{0,1000}0bin\s\-\sencrypted\spastebin.{0,1000} | greyware_tool_keyword | 0bin.net | Accessing a paste on 0bin.net | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Collection | https://0bin.net | 1 | 0 | #PastebinLike | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 21511 |
| 211 | *0d773444d899ab08f8aaee56dec0fb17928784dca205ef25af61a71bf4fb6e3f* | .{0,1000}0d773444d899ab08f8aaee56dec0fb17928784dca205ef25af61a71bf4fb6e3f.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 21628 | |
| 212 | *0DF38AD4-60AF-4F93-9C7A-7FB7BA692017* | .{0,1000}0DF38AD4\-60AF\-4F93\-9C7A\-7FB7BA692017.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | #GUIDproject | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 21671 |
| 213 | *0xthirteen/Carseat* | .{0,1000}0xthirteen\/Carseat.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 1 | N/A | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 21856 |
| 214 | *15a2171b1424a78028131808a24d39d5f5383cfd4540ea360a74f9b7c752933d* | .{0,1000}15a2171b1424a78028131808a24d39d5f5383cfd4540ea360a74f9b7c752933d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 22272 |
| 215 | *1ae56e7ebbdbbd3912b3bec2f08c065895e82492494c26d076cce466dd0572ad* | .{0,1000}1ae56e7ebbdbbd3912b3bec2f08c065895e82492494c26d076cce466dd0572ad.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 22637 |
| 216 | *1ea81f89cfaaf2fe3273f042bb4eaafc1046fbc3ceb146b79eee8a898a189b45* | .{0,1000}1ea81f89cfaaf2fe3273f042bb4eaafc1046fbc3ceb146b79eee8a898a189b45.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 22923 |
| 217 | *1fc325f3-c548-43db-a13f-8c460dda8381* | .{0,1000}1fc325f3\-c548\-43db\-a13f\-8c460dda8381.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 0 | #GUIDproject | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 23002 |
| 218 | *216244b421d1ebb05ea81496831a2893139d6e2329db77e39cd6a2dc08e703e8* | .{0,1000}216244b421d1ebb05ea81496831a2893139d6e2329db77e39cd6a2dc08e703e8.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 23131 | |
| 219 | *2236b69f5c5c266ca57af9f9a2fddd35a36b4dd4de5ee279f87d2bf2e769bc81* | .{0,1000}2236b69f5c5c266ca57af9f9a2fddd35a36b4dd4de5ee279f87d2bf2e769bc81.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 23195 |
| 220 | *28f3463d7e6c3c5cc339f624712cee8e8277fffc2c6a4bf356cd4cb59ab4efce* | .{0,1000}28f3463d7e6c3c5cc339f624712cee8e8277fffc2c6a4bf356cd4cb59ab4efce.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 23655 |
| 221 | *2e7780d7593f341c0b72ad38f91638cfbb917e7f9f342b3ffaa842d207d4ab85* | .{0,1000}2e7780d7593f341c0b72ad38f91638cfbb917e7f9f342b3ffaa842d207d4ab85.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24011 |
| 222 | *3002cc4ccf57741919e563283d63b762f29512aafe16837b297c6d70e014bd04* | .{0,1000}3002cc4ccf57741919e563283d63b762f29512aafe16837b297c6d70e014bd04.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24160 |
| 223 | *3170917f0dbe26d4a09283394af0b9a9e9724589cd650d0b451b2c834aab3bf6* | .{0,1000}3170917f0dbe26d4a09283394af0b9a9e9724589cd650d0b451b2c834aab3bf6.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #filehash | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 24257 |
| 224 | *33b54c9b555472d471ff2eb145156d7212e13ad4282b020527267ca42c2afafe* | .{0,1000}33b54c9b555472d471ff2eb145156d7212e13ad4282b020527267ca42c2afafe.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 24425 | |
| 225 | *34b57458547e8ecd072caffdd5f390098197f2bef7cee067b0122b2c153f4b01* | .{0,1000}34b57458547e8ecd072caffdd5f390098197f2bef7cee067b0122b2c153f4b01.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24498 |
| 226 | *35c64b018248a12e677777eab956c086212a2fe5d7206e76d66ac5dc9fa41103* | .{0,1000}35c64b018248a12e677777eab956c086212a2fe5d7206e76d66ac5dc9fa41103.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24559 |
| 227 | *36a51b581592148e33c4f47c4e4f72710564595b6147b732e203d27a6d7dabb5* | .{0,1000}36a51b581592148e33c4f47c4e4f72710564595b6147b732e203d27a6d7dabb5.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24612 |
| 228 | *39832c87758a620ccc75fcbdacee79993652fd81597ce79f52bab3f4b9abd2a5* | .{0,1000}39832c87758a620ccc75fcbdacee79993652fd81597ce79f52bab3f4b9abd2a5.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 24833 |
| 229 | *3c9f2deb4c664d6321474815f4fefa2c80778fe2da2a9a35d1a31f2f9106bf96* | .{0,1000}3c9f2deb4c664d6321474815f4fefa2c80778fe2da2a9a35d1a31f2f9106bf96.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 25046 |
| 230 | *3dca957edf214b435721c18bbacef52a660d618150453589bd95631eb92b5cc8* | .{0,1000}3dca957edf214b435721c18bbacef52a660d618150453589bd95631eb92b5cc8.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 25121 | |
| 231 | *3ec8a46dfacff51b3a19034479c2c68b74c92342e483295152754f939a8d1d31* | .{0,1000}3ec8a46dfacff51b3a19034479c2c68b74c92342e483295152754f939a8d1d31.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #filehash | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 25185 |
| 232 | *417f92b83d18cb5d231496fde3d743a34d2f483c26cf831742e30cc11c3963bb* | .{0,1000}417f92b83d18cb5d231496fde3d743a34d2f483c26cf831742e30cc11c3963bb.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 25417 |
| 233 | *41fe9889b428813cda89d017204555e013cf5c081122cd821f6c343ccc2ffcb7* | .{0,1000}41fe9889b428813cda89d017204555e013cf5c081122cd821f6c343ccc2ffcb7.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 25461 |
| 234 | *4374b7f67ac23d9fc63fac8b9da7e279edd897ee5854d6a67c64ec648974e3fa* | .{0,1000}4374b7f67ac23d9fc63fac8b9da7e279edd897ee5854d6a67c64ec648974e3fa.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 25565 |
| 235 | *450746e51e6f1369e7e73c5e2122d0ca81153d3a4c7bcec3d66266b15ee547f7* | .{0,1000}450746e51e6f1369e7e73c5e2122d0ca81153d3a4c7bcec3d66266b15ee547f7.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #filehash | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 25682 |
| 236 | *49c9788a669f864351f347d5f13e34cab961a6bc88afe5f8a5e32e868a2fc81d* | .{0,1000}49c9788a669f864351f347d5f13e34cab961a6bc88afe5f8a5e32e868a2fc81d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26012 |
| 237 | *4a613d768611d513d39de2212129c8fe56b77c016b0818584a3ca3cfd6a9bcaf* | .{0,1000}4a613d768611d513d39de2212129c8fe56b77c016b0818584a3ca3cfd6a9bcaf.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 26044 | |
| 238 | *4a852249475372d387ac1ba1c5ccd8b541dac4d89fb4ec51877cad81024a0c08* | .{0,1000}4a852249475372d387ac1ba1c5ccd8b541dac4d89fb4ec51877cad81024a0c08.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26050 |
| 239 | *4b6df010ff6834f9d493d178079730ebd03f3fefd7a1e8da6c4456f2ed8d6296* | .{0,1000}4b6df010ff6834f9d493d178079730ebd03f3fefd7a1e8da6c4456f2ed8d6296.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26131 |
| 240 | *4c230850f0fab974effc07d9ac7df6d11f2d49cac19d71da269d1c1d18e574e2* | .{0,1000}4c230850f0fab974effc07d9ac7df6d11f2d49cac19d71da269d1c1d18e574e2.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26194 |
| 241 | *4cc3c88b175e7c6c9e881707ab3a6b956c7cbcb69a5f61d417d4736f054677b4* | .{0,1000}4cc3c88b175e7c6c9e881707ab3a6b956c7cbcb69a5f61d417d4736f054677b4.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 0 | #filehash | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 26247 |
| 242 | *4fcf193202e55eff267792c86cea4098711b24d3fa0cca8e03027da2ddb3206a* | .{0,1000}4fcf193202e55eff267792c86cea4098711b24d3fa0cca8e03027da2ddb3206a.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #filehash | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 26455 |
| 243 | *50C0BF9479EFC93FA9CF1AA99BD?CA923273B71A1* | .{0,1000}50C0BF9479EFC93FA9CF1AA99BD\?CA923273B71A1.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 26528 | |
| 244 | *50c461593a4ad6f09903a04e528de6991e745be1a7b444c002987348d921fcb0* | .{0,1000}50c461593a4ad6f09903a04e528de6991e745be1a7b444c002987348d921fcb0.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26530 |
| 245 | *52b6c057a9e0af822cbe129053d2c2d3541bf6e9ef162432fae60fdbd7a2d0f0* | .{0,1000}52b6c057a9e0af822cbe129053d2c2d3541bf6e9ef162432fae60fdbd7a2d0f0.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #filehash | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 26684 |
| 246 | *537fee794fe5532349360a40d90c0e0e37f9532b0101dbb17174e27cc4aa0d51* | .{0,1000}537fee794fe5532349360a40d90c0e0e37f9532b0101dbb17174e27cc4aa0d51.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26738 |
| 247 | *568a162e78cabe48a7f30df47b2435b211549e9a7bc7a06f0802b6fc07b7cc94* | .{0,1000}568a162e78cabe48a7f30df47b2435b211549e9a7bc7a06f0802b6fc07b7cc94.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 26958 |
| 248 | *59156b50c20d44f8757a3a53ebaf4f515b8eb86802ee51085ace7b1f714406ce* | .{0,1000}59156b50c20d44f8757a3a53ebaf4f515b8eb86802ee51085ace7b1f714406ce.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 27173 |
| 249 | *5943462569081cec86ed241964fbccf91b4be608c2d647470b19afe31549adc5* | .{0,1000}5943462569081cec86ed241964fbccf91b4be608c2d647470b19afe31549adc5.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 27180 |
| 250 | *5b5f70992a0d5a59176a7bfb43401d56ab3d250958378f1d913405040bf7cf54* | .{0,1000}5b5f70992a0d5a59176a7bfb43401d56ab3d250958378f1d913405040bf7cf54.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 27341 | |
| 251 | *5ba1b5f60649f253556fa044849ea7af38cef5337c5061f06004687e0862d6c3* | .{0,1000}5ba1b5f60649f253556fa044849ea7af38cef5337c5061f06004687e0862d6c3.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 27359 |
| 252 | *5db320e5c5cbbc14478fc1d7c7ae33cfff92877fc585f83a3d7a981a00e9b4f4* | .{0,1000}5db320e5c5cbbc14478fc1d7c7ae33cfff92877fc585f83a3d7a981a00e9b4f4.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 27519 |
| 253 | *5db3498c96a63ebbf02ce68726110bdc2111cdd4d8bbd3e75d37e8055e8cb3e7* | .{0,1000}5db3498c96a63ebbf02ce68726110bdc2111cdd4d8bbd3e75d37e8055e8cb3e7.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 27520 |
| 254 | *63ec96c5-075f-4f22-92ec-cf28a2f70737* | .{0,1000}63ec96c5\-075f\-4f22\-92ec\-cf28a2f70737.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #GUIDproject | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 27941 |
| 255 | *6ef7a5a0d7eb7976141aa9d61242969b0dee3e8a7dddb6259c1bd539b68dcad8* | .{0,1000}6ef7a5a0d7eb7976141aa9d61242969b0dee3e8a7dddb6259c1bd539b68dcad8.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 28654 |
| 256 | *71bda8ea-08bc-4ab1-9b40-614b167beb64* | .{0,1000}71bda8ea\-08bc\-4ab1\-9b40\-614b167beb64.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #GUIDproject | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 28848 |
| 257 | *73c49b77b6b2e4032eacfc94d5e5e2bd185fc8ce7eba23ed4ca6921ceb631614* | .{0,1000}73c49b77b6b2e4032eacfc94d5e5e2bd185fc8ce7eba23ed4ca6921ceb631614.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 28998 |
| 258 | *7454351714f775b8391bc42fb94e929c87850debadc69d48a40ac7d9584e1211* | .{0,1000}7454351714f775b8391bc42fb94e929c87850debadc69d48a40ac7d9584e1211.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 29038 |
| 259 | *7ce28732993dacc199e5f96517aa1d16305c86c623a0e17f9923838e3fa06133* | .{0,1000}7ce28732993dacc199e5f96517aa1d16305c86c623a0e17f9923838e3fa06133.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 29644 |
| 260 | *7da1b05ebb0a51e4160ea04db4f70b6e710c14546d5a13169942e4d686bdc477* | .{0,1000}7da1b05ebb0a51e4160ea04db4f70b6e710c14546d5a13169942e4d686bdc477.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 29694 |
| 261 | *828411d980e653c3fa63dd031839e52ae1800b4f29f3b03f7acad492811dce2b* | .{0,1000}828411d980e653c3fa63dd031839e52ae1800b4f29f3b03f7acad492811dce2b.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #filehash | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 30052 |
| 262 | *8340cdf3b69ba92b47803f75eabb102d35454ef9676702ff1742c7136d9608de* | .{0,1000}8340cdf3b69ba92b47803f75eabb102d35454ef9676702ff1742c7136d9608de.{0,1000} | offensive_tool_keyword | keylogger | Keyboard recording | T1056.001 | TA0006 - TA0009 | N/A | N/A | Collection | https://github.com/uknowsec/keylogger | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 35 | 2021-05-19T08:33:58Z | 2020-11-10T07:15:50Z | 30112 |
| 263 | *85239f4abe215e87a147a6f63e8a281c2c3a687dcc45d430042c1e897de36696* | .{0,1000}85239f4abe215e87a147a6f63e8a281c2c3a687dcc45d430042c1e897de36696.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #filehash | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 30241 |
| 264 | *85a88db7ae01c7735386630ef780fbabdf465b9b9fb1e30e5ea698b114a33540* | .{0,1000}85a88db7ae01c7735386630ef780fbabdf465b9b9fb1e30e5ea698b114a33540.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 30273 |
| 265 | *868d0fe76c71f94336e0444d1b4ce6d7bdd2d0c71dcc2befa9ba1a1d3bb6d28f* | .{0,1000}868d0fe76c71f94336e0444d1b4ce6d7bdd2d0c71dcc2befa9ba1a1d3bb6d28f.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 30316 |
| 266 | *89a687f0367983c98008e9bd2d82e6aa579e24f2d702b6912eeae74b21e85dc9* | .{0,1000}89a687f0367983c98008e9bd2d82e6aa579e24f2d702b6912eeae74b21e85dc9.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #filehash | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 30544 |
| 267 | *8d352347e622b8ff6babf1a119266f59c1b14a48cebc4cb2cf84c00edd276fe3* | .{0,1000}8d352347e622b8ff6babf1a119266f59c1b14a48cebc4cb2cf84c00edd276fe3.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #filehash | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 30817 |
| 268 | *920021c608185f95a4100ebec9e7c0fb4c67c1d192257ba9ac3430b2939762a3* | .{0,1000}920021c608185f95a4100ebec9e7c0fb4c67c1d192257ba9ac3430b2939762a3.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 0 | #filehash | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 31154 |
| 269 | *922d41ca55d3fa150f1c8fdc1f030e2acf6c24fcbd0ce1cd1021aeffe29bf24c* | .{0,1000}922d41ca55d3fa150f1c8fdc1f030e2acf6c24fcbd0ce1cd1021aeffe29bf24c.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #filehash | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 31169 |
| 270 | *93a9468ea39b4bb15148e4845593d36f0137c5a23de9045dc5596a302f873e16* | .{0,1000}93a9468ea39b4bb15148e4845593d36f0137c5a23de9045dc5596a302f873e16.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 31274 |
| 271 | *94e25cf9677638da8ddfd84a2c15783e894de90331ed06e9786b1a46df1915fb* | .{0,1000}94e25cf9677638da8ddfd84a2c15783e894de90331ed06e9786b1a46df1915fb.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 31355 |
| 272 | *975b49f84c3e34d26052f938c50aa5856cccbbdf32e9e4698cebba577ed10c8c* | .{0,1000}975b49f84c3e34d26052f938c50aa5856cccbbdf32e9e4698cebba577ed10c8c.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 31528 |
| 273 | *9a33a8d19676646badef58d0a2db13dd763288a2a0fb8452ae2a9f826b27a234* | .{0,1000}9a33a8d19676646badef58d0a2db13dd763288a2a0fb8452ae2a9f826b27a234.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 31720 |
| 274 | *9CD?F6D5878FC3AECF10761FD72371A2877F270D0* | .{0,1000}9CD\?F6D5878FC3AECF10761FD72371A2877F270D0.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 31892 | |
| 275 | *9D1C563E5228B2572F5CA14F0EC33?CA0DEDA3D57* | .{0,1000}9D1C563E5228B2572F5CA14F0EC33\?CA0DEDA3D57.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 31916 | |
| 276 | *9f9141f57f4d135a00557547091b73f9b13b0af2346082a243e65af90cb9be7e* | .{0,1000}9f9141f57f4d135a00557547091b73f9b13b0af2346082a243e65af90cb9be7e.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 32088 |
| 277 | *A client side encrypted PasteBin* | .{0,1000}A\sclient\sside\sencrypted\sPasteBin.{0,1000} | greyware_tool_keyword | 0bin.net | Accessing a paste on 0bin.net | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Collection | https://0bin.net | 1 | 0 | #content #PastebinLike | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 32125 |
| 278 | *a287b6d1ff18dab39efbf0b4c6937507f388923cbb47e66d72938aa87912bc20* | .{0,1000}a287b6d1ff18dab39efbf0b4c6937507f388923cbb47e66d72938aa87912bc20.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 32336 | |
| 279 | *a583acecdb43cd9b4806eddcf0582ec0cfd9281a2ff821b3d35c4d2dd6103eeb* | .{0,1000}a583acecdb43cd9b4806eddcf0582ec0cfd9281a2ff821b3d35c4d2dd6103eeb.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 32539 |
| 280 | *a71a8916d6a82bcd0d80cc8150699754abdd4c165773438b9ed39515372a4ec8* | .{0,1000}a71a8916d6a82bcd0d80cc8150699754abdd4c165773438b9ed39515372a4ec8.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 32652 |
| 281 | *ab36a5c1f20df8fb1b59154aa6aa83bba2d29a6925fb9ec134457e7d1c95bb7a* | .{0,1000}ab36a5c1f20df8fb1b59154aa6aa83bba2d29a6925fb9ec134457e7d1c95bb7a.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 32973 |
| 282 | *abdullahansari1618@outlook.com* | .{0,1000}abdullahansari1618\@outlook\.com.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 33030 | |
| 283 | *akoofbljmjeodfmdpjndmmnifglppjdi* | .{0,1000}akoofbljmjeodfmdpjndmmnifglppjdi.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #browser_extensionid | https://github.com/mthcht/awesome-lists/blob/41d3934b5b76aaf7555d980197d1e8b5c55f1fb3/Lists/Browser%20Extensions/browser_extensions_list.csv#L2 | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 33775 |
| 284 | *API::installHook() - Windows keyboard hook could not be installed!* | .{0,1000}API\:\:installHook\(\)\s\-\sWindows\skeyboard\shook\scould\snot\sbe\sinstalled!.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 33949 |
| 285 | *app.config['graph_spy_db_folder']* | .{0,1000}app\.config\[\'graph_spy_db_folder\'\].{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #content | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 33964 |
| 286 | *app.config['graph_spy_db_path']* | .{0,1000}app\.config\[\'graph_spy_db_path\'\].{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #content | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 33965 |
| 287 | *arp_mitm.py* | .{0,1000}arp_mitm\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 34072 |
| 288 | *b2956027022f69baa93e6c55c69df6ace602d6ad61cb4ddfdaedd4c9be46d7b6* | .{0,1000}b2956027022f69baa93e6c55c69df6ace602d6ad61cb4ddfdaedd4c9be46d7b6.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34571 |
| 289 | *b2b19b7cfc5f45ffcd83e6a099c40ba085cb86c4ab0ac4d0d4ad6aa8e0f40c4c* | .{0,1000}b2b19b7cfc5f45ffcd83e6a099c40ba085cb86c4ab0ac4d0d4ad6aa8e0f40c4c.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34582 |
| 290 | *b4ac2390829f0e3a76c51692d27759ca7b83b4459c4707e86d59c72dbbbe36d3* | .{0,1000}b4ac2390829f0e3a76c51692d27759ca7b83b4459c4707e86d59c72dbbbe36d3.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34718 |
| 291 | *b5cbcd477e65b4fad4c55e22043eda8859bab60bbdaad28386cf5a70f04299cd* | .{0,1000}b5cbcd477e65b4fad4c55e22043eda8859bab60bbdaad28386cf5a70f04299cd.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 34805 | |
| 292 | *b62764ff67244482f88ef117bf69d4ee51dc1691f6a62f3feab2dff8e94b9cdf* | .{0,1000}b62764ff67244482f88ef117bf69d4ee51dc1691f6a62f3feab2dff8e94b9cdf.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34833 |
| 293 | *b7291585c934f4554e645642cebf82f663316646ccf4360f356ff535d2d6c969* | .{0,1000}b7291585c934f4554e645642cebf82f663316646ccf4360f356ff535d2d6c969.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34910 |
| 294 | *b809230b5259568f275760187a0eb5c2cd00a6ac859d92e685036c1dfb797f0d* | .{0,1000}b809230b5259568f275760187a0eb5c2cd00a6ac859d92e685036c1dfb797f0d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 34978 |
| 295 | *b88e406cbf20a830e357e89a3e3aa4210829777d43a5fb11d46e38a4220f4d9a* | .{0,1000}b88e406cbf20a830e357e89a3e3aa4210829777d43a5fb11d46e38a4220f4d9a.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 35018 |
| 296 | *B948E25D061039D64115CFDE74D2FF4372E83765* | .{0,1000}B948E25D061039D64115CFDE74D2FF4372E83765.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 35063 | |
| 297 | *ba7aa4e5aba5fa90f17a2aca9cee62a2b01bb1fc91f6433643e48cdfa4b1c03d* | .{0,1000}ba7aa4e5aba5fa90f17a2aca9cee62a2b01bb1fc91f6433643e48cdfa4b1c03d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 35125 |
| 298 | *bitsadmin /transfer * | .{0,1000}bitsadmin\s\/transfer\s.{0,1000} | greyware_tool_keyword | bitsadmin | bitsadmin suspicious transfer | T1105 - T1041 - T1048 | TA0002 - TA0003 - TA0010 | N/A | Black Basta - Hive - Revil - Conti - Medusa | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 35991 |
| 299 | *bitsadmin /transfer debjob /download /priority normal \*\C$\Windows\*.dll | .{0,1000}bitsadmin\s\/transfer\sdebjob\s\/download\s\/priority\snormal\s\\.{0,1000}\\C\$\\Windows\\.{0,1000}\.dll | greyware_tool_keyword | bitsadmin | bitsadmin suspicious transfer | T1105 - T1041 - T1048 | TA0002 - TA0003 - TA0010 | N/A | Black Basta - Hive - Revil - Conti - Medusa | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 35992 |
| 300 | *bWFsd2FyZQ==* | .{0,1000}bWFsd2FyZQ\=\=.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 36430 | |
| 301 | *c1c9047d94569bf28c91247cfa84cb49c5d49e37eaae46804663a6d1f45b615d* | .{0,1000}c1c9047d94569bf28c91247cfa84cb49c5d49e37eaae46804663a6d1f45b615d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 36752 |
| 302 | *c3444ec251cca27dd59adbfbc995f095550b7e7e25623f46799e03584845b3b9* | .{0,1000}c3444ec251cca27dd59adbfbc995f095550b7e7e25623f46799e03584845b3b9.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 36904 |
| 303 | *c3l3si4n/webtrufflehog* | .{0,1000}c3l3si4n\/webtrufflehog.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 1 | N/A | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 36964 |
| 304 | *c4e9806596b8e6123a595395b0efe604176dfd2e767418fe4adf69c70de557b5* | .{0,1000}c4e9806596b8e6123a595395b0efe604176dfd2e767418fe4adf69c70de557b5.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 0 | #filehash | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 37021 |
| 305 | *c7ef467eeb99aa4aae717d0e258019ab5b7e176da4906a135d86e78faa9251cc* | .{0,1000}c7ef467eeb99aa4aae717d0e258019ab5b7e176da4906a135d86e78faa9251cc.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 37250 |
| 306 | *c8bdc5ce227d167f87797e8f7b3d91d24cd40c0925f5f6406085ad8cdf455617* | .{0,1000}c8bdc5ce227d167f87797e8f7b3d91d24cd40c0925f5f6406085ad8cdf455617.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | #filehash | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 37314 |
| 307 | *CarSeat: A junior Seatbelt\n* | .{0,1000}CarSeat\:\sA\sjunior\sSeatbelt\\n.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #content | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 37586 |
| 308 | *cc5b8ca570f2f1aa9aed761a466007e7bd4b807f823e5add1d10fb732a034e9c* | .{0,1000}cc5b8ca570f2f1aa9aed761a466007e7bd4b807f823e5add1d10fb732a034e9c.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 37752 | |
| 309 | *cd2e2beff40caf56b5102947d81e825f44b8df24d84f5dc49b1c850f4dca40a9* | .{0,1000}cd2e2beff40caf56b5102947d81e825f44b8df24d84f5dc49b1c850f4dca40a9.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 37848 |
| 310 | *cdc1690245f3c8749c1ee9744540aa4df2b784f69cb425a967249c057b9799e8* | .{0,1000}cdc1690245f3c8749c1ee9744540aa4df2b784f69cb425a967249c057b9799e8.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 37897 |
| 311 | *ce75ede7827b5a067bb11a5153e3046286251acaf1e92fd3edf4a46e506b5968* | .{0,1000}ce75ede7827b5a067bb11a5153e3046286251acaf1e92fd3edf4a46e506b5968.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 37968 |
| 312 | *certoc.exe -GetCACAPS https://raw.githubusercontent.com* | .{0,1000}certoc\.exe\s\-GetCACAPS\shttps\:\/\/raw\.githubusercontent\.com.{0,1000} | greyware_tool_keyword | certoc | download from github with certoc | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | N/A | Collection | https://lolbas-project.github.io/lolbas/Binaries/Certoc/ | 1 | 0 | N/A | lolbin | 8 | 9 | N/A | N/A | N/A | N/A | 38026 |
| 313 | *certutil -urlcache -split -f http*.exe* | .{0,1000}certutil\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | certutil | Certutil download behavior observed by APT41 group | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | APT41 | Collection | https://detect.fyi/playbook-hunting-chinese-apt-379a6b950492 | 1 | 0 | N/A | lolbin | 8 | 9 | N/A | N/A | N/A | N/A | 38036 |
| 314 | *certutil.exe -urlcache -split -f *https://cdn.discordapp.com/attachments/* | .{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\s.{0,1000}https\:\/\/cdn\.discordapp\.com\/attachments\/.{0,1000} | greyware_tool_keyword | certutil | LOLBAS execution - downloading payload from discord with certutil | T1105 - T1218.010 - T1071.001 - T1036.005 | TA0009 - TA0002 - TA0005 | N/A | CHRYSENE - GOLD SOUTHFIELD | Collection | N/A | 1 | 0 | N/A | lolbin | 10 | 10 | N/A | N/A | N/A | N/A | 38037 |
| 315 | *certutil.exe -urlcache -split -f http*.bat C:\ProgramData\* | .{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.bat\sC\:\\ProgramData\\.{0,1000} | greyware_tool_keyword | certutil | Certutil download behavior observed by the Dispossessor ransomware group | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | Dispossessor | Collection | N/A | 1 | 0 | N/A | lolbin | 10 | 10 | N/A | N/A | N/A | N/A | 38038 |
| 316 | *certutil.exe -urlcache -split -f http*.ps1 C:\ProgramData\* | .{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.ps1\sC\:\\ProgramData\\.{0,1000} | greyware_tool_keyword | certutil | Certutil download behavior observed by the Dispossessor ransomware group | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | Dispossessor | Collection | N/A | 1 | 0 | N/A | lolbin | 10 | 10 | N/A | N/A | N/A | N/A | 38039 |
| 317 | *certutil.exe -urlcache -split -f http*.vbs C:\ProgramData\* | .{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttp.{0,1000}\.vbs\sC\:\\ProgramData\\.{0,1000} | greyware_tool_keyword | certutil | Certutil download behavior observed by the Dispossessor ransomware group | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | Dispossessor | Collection | N/A | 1 | 0 | N/A | lolbin | 10 | 10 | N/A | N/A | N/A | N/A | 38040 |
| 318 | *certutil.exe -urlcache -split -f https://raw.githubusercontent.com/* | .{0,1000}certutil\.exe\s\-urlcache\s\-split\s\-f\shttps\:\/\/raw\.githubusercontent\.com\/.{0,1000} | greyware_tool_keyword | certutil | Certutil Download from github | T1105 - T1566.001 - T1071.001 | TA0009 - TA0005 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | lolbin | 8 | 9 | N/A | N/A | N/A | N/A | 38041 |
| 319 | *change-windows10-mac-address.py* | .{0,1000}change\-windows10\-mac\-address\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 38126 |
| 320 | *cmd /C reg export hkcu* | .{0,1000}cmd\s\/C\sreg\sexport\shkcu.{0,1000} | greyware_tool_keyword | reg | exporting registry keys | T1012 | TA0009 | N/A | N/A | Collection | https://blog.talosintelligence.com/uat-5647-romcom/ | 1 | 0 | #registry | N/A | 5 | 6 | N/A | N/A | N/A | N/A | 38402 |
| 321 | *cmd /C reg export hklm* | .{0,1000}cmd\s\/C\sreg\sexport\shklm.{0,1000} | greyware_tool_keyword | reg | exporting registry keys | T1012 | TA0009 | N/A | N/A | Collection | https://blog.talosintelligence.com/uat-5647-romcom/ | 1 | 0 | #registry | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 38403 |
| 322 | *cmd.exe* /c echo curl https://* --output "%temp%* --ssl no-revoke --insecure --location > "%temp%* | .{0,1000}cmd\.exe.{0,1000}\s\/c\secho\scurl\shttps\:\/\/.{0,1000}\s\-\-output\s\"\%temp\%.{0,1000}\s\-\-ssl\sno\-revoke\s\-\-insecure\s\-\-location\s\>\s\"\%temp\%.{0,1000} | greyware_tool_keyword | curl | potential suspicious curl command - downloading payload in the temp directory | T1105 - T1059.003 | TA0005 | N/A | N/A | Collection | https://thedfirreport.com/2024/04/29/from-icedid-to-dagon-locker-ransomware-in-29-days/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38464 |
| 323 | *codeload.github.com/* | .{0,1000}codeload\.github\.com\/.{0,1000} | greyware_tool_keyword | github | Github executables download initiated - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 38576 |
| 324 | *copy *NTDS\NTDS.dit*Temp* | .{0,1000}copy\s.{0,1000}NTDS\\NTDS\.dit.{0,1000}Temp.{0,1000} | greyware_tool_keyword | copy | copy the NTDS.dit file from a Volume Shadow Copy which contains sensitive Active Directory data including password hashes for all domain users | T1003.003 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 38875 |
| 325 | *copy *sam.hive \\* | .{0,1000}copy\s.{0,1000}sam\.hive\s\\\\.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 38877 |
| 326 | *copy *system.hive \\* | .{0,1000}copy\s.{0,1000}system\.hive\s\\\\.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 38878 |
| 327 | *csvde -f * | .{0,1000}csvde\s\-f\s.{0,1000} | greyware_tool_keyword | csvde | exports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) format | T1005 | TA0009 - TA0007 | N/A | N/A | Collection | https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11) | 1 | 0 | N/A | N/A | 9 | 9 | N/A | N/A | N/A | N/A | 39175 |
| 328 | *csvde -r * -f * | .{0,1000}csvde\s\-r\s.{0,1000}\s\-f\s.{0,1000} | greyware_tool_keyword | csvde | exports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) format | T1005 | TA0009 - TA0007 | N/A | N/A | Collection | https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11) | 1 | 0 | N/A | N/A | 9 | 9 | N/A | N/A | N/A | N/A | 39176 |
| 329 | *csvde.exe -f * | .{0,1000}csvde\.exe\s\-f\s.{0,1000} | greyware_tool_keyword | csvde | exports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) format | T1005 | TA0009 - TA0007 | N/A | N/A | Collection | https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11) | 1 | 0 | N/A | N/A | 9 | 9 | N/A | N/A | N/A | N/A | 39177 |
| 330 | *csvde.exe -r * -f * | .{0,1000}csvde\.exe\s\-r\s.{0,1000}\s\-f\s.{0,1000} | greyware_tool_keyword | csvde | exports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) format | T1005 | TA0009 - TA0007 | N/A | N/A | Collection | https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11) | 1 | 0 | N/A | N/A | 9 | 9 | N/A | N/A | N/A | N/A | 39178 |
| 331 | *csvde.exe" -f * | .{0,1000}csvde\.exe\"\s\-f\s.{0,1000} | greyware_tool_keyword | csvde | exports data from Active Directory Domain Services (AD DS) using files that store data in the comma-separated value (CSV) format | T1005 | TA0009 - TA0007 | N/A | N/A | Collection | https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc732101(v=ws.11) | 1 | 0 | N/A | N/A | 9 | 9 | N/A | N/A | N/A | N/A | 39179 |
| 332 | *curl https://termbin.com/* | .{0,1000}curl\shttps\:\/\/termbin\.com\/.{0,1000} | greyware_tool_keyword | termbin.com | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | termbin.com | 1 | 0 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 39208 |
| 333 | *curl*nopaste.net* | .{0,1000}curl.{0,1000}nopaste\.net.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Collection | https://www.shellhub.io/ | 1 | 0 | #Pastebinlike #filehostingservice #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 39221 |
| 334 | *d3a7210d3999176aaea1f64927668d443bffbd764fe113e2869b1ad03c2d3013* | .{0,1000}d3a7210d3999176aaea1f64927668d443bffbd764fe113e2869b1ad03c2d3013.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 39612 | |
| 335 | *D3DF3F32716042404798E3E9D691ACED2F78BD?D5* | .{0,1000}D3DF3F32716042404798E3E9D691ACED2F78BD\?D5.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 39628 | |
| 336 | *d62a0e8ea863d3812dcbf3927534db6b2a82223f2bfd2c374c7263be98b855f1* | .{0,1000}d62a0e8ea863d3812dcbf3927534db6b2a82223f2bfd2c374c7263be98b855f1.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #filehash | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 39780 |
| 337 | *df68fb1553a6d135354adb6d2cc68ea5b0b63569e8d2c6bf5659869cf94ae4cc* | .{0,1000}df68fb1553a6d135354adb6d2cc68ea5b0b63569e8d2c6bf5659869cf94ae4cc.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 40818 |
| 338 | *disk2vhd.exe* | .{0,1000}disk2vhd\.exe.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41032 |
| 339 | *Disk2vhd.zip* | .{0,1000}Disk2vhd\.zip.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41033 |
| 340 | *disk2vhd64.exe* | .{0,1000}disk2vhd64\.exe.{0,1000} | greyware_tool_keyword | Disk2vhd | convert physical disks into Virtual Hard Disk (VHD) files -attackers can leverage it for Collection | T1560.002 - T1012 - T1560.003 | TA0005 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 41034 |
| 341 | *DNS-Tunnel-Keylogger* | .{0,1000}DNS\-Tunnel\-Keylogger.{0,1000} | offensive_tool_keyword | DNS-Tunnel-Keylogger | Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes | T1056.001 - T1048.003 | TA0009 - TA0011 | N/A | N/A | Collection | https://github.com/Geeoon/DNS-Tunnel-Keylogger | 1 | 1 | N/A | N/A | 9 | 3 | 273 | 40 | 2024-06-16T19:47:36Z | 2024-01-10T17:25:58Z | 41290 |
| 342 | *docker run */.config/pcopy* | .{0,1000}docker\srun\s.{0,1000}\/\.config\/pcopy.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Collection | https://www.shellhub.io/ | 1 | 0 | #Pastebinlike #filehostingservice #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 41328 |
| 343 | *download keylog.exe* | .{0,1000}download\skeylog\.exe.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 41454 | |
| 344 | *dpapi.py backupkeys -t */*@* | .{0,1000}dpapi\.py\sbackupkeys\s\-t\s.{0,1000}\/.{0,1000}\@.{0,1000} | greyware_tool_keyword | dpapi.py | the command is used to extract the Data Protection API (DPAPI) backup keys from a target system. DPAPI is a Windows API that provides data protection services to secure sensitive data. such as private keys. passwords. and other secrets. By obtaining the DPAPI backup keys. an attacker can potentially decrypt sensitive data stored on the target system or impersonate users. gaining unauthorized access to other systems and resources. | T1552.006 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 41497 |
| 345 | *e2bff960e45f419ca14338dcdefdcfe25378bc5efa56adfb762ebca92847d86f* | .{0,1000}e2bff960e45f419ca14338dcdefdcfe25378bc5efa56adfb762ebca92847d86f.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 41922 |
| 346 | *e49c11f8f47b6fe4c3810ad8b5a241638983d7e60d240f70859fd4b7a887c4d6* | .{0,1000}e49c11f8f47b6fe4c3810ad8b5a241638983d7e60d240f70859fd4b7a887c4d6.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 42051 |
| 347 | *e58c52c3eb69dc4b6cf3a73a42c7a9bc3adc4d0e4728a2a8744715fc730f8b9d* | .{0,1000}e58c52c3eb69dc4b6cf3a73a42c7a9bc3adc4d0e4728a2a8744715fc730f8b9d.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 42121 |
| 348 | *e803b7023dfdcb1d73de9a04be5222269b020ada4fcc97ca19ef877c55a51c28* | .{0,1000}e803b7023dfdcb1d73de9a04be5222269b020ada4fcc97ca19ef877c55a51c28.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 42310 | |
| 349 | *ebef8a0206bb0550926511265edc977c0a75de6dd8a03be4e228cf708ac64c24* | .{0,1000}ebef8a0206bb0550926511265edc977c0a75de6dd8a03be4e228cf708ac64c24.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 42594 |
| 350 | *EC54E?F8D79BF30B63C5249AF7A8A3C652595B923* | .{0,1000}EC54E\?F8D79BF30B63C5249AF7A8A3C652595B923.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 42629 | |
| 351 | *ec6e3c3f97578eeeb27f891b19c4504e038e0488293eb1f3c50d3bdc2f30b017* | .{0,1000}ec6e3c3f97578eeeb27f891b19c4504e038e0488293eb1f3c50d3bdc2f30b017.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 42638 |
| 352 | *EDR Detector by trickster0* | .{0,1000}EDR\sDetector\sby\strickster0.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 0 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 42823 |
| 353 | *EDR_Detection.exe* | .{0,1000}EDR_Detection\.exe.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 42824 |
| 354 | *EDR_Detector.7z* | .{0,1000}EDR_Detector\.7z.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 42825 |
| 355 | *EDR_Detector-master* | .{0,1000}EDR_Detector\-master.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 42826 |
| 356 | *Exfiltrate::exfilLogs()* | .{0,1000}Exfiltrate\:\:exfilLogs\(\).{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 43529 |
| 357 | *f0037d99bc3119fc613d304af20599e8c791b1c99208d5d452a01738777f7b49* | .{0,1000}f0037d99bc3119fc613d304af20599e8c791b1c99208d5d452a01738777f7b49.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #filehash | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 43673 |
| 358 | *f4c91aebc3bbf867adc0ade2b4d82ffd1753a396143ce8e462b6460736efdbfd* | .{0,1000}f4c91aebc3bbf867adc0ade2b4d82ffd1753a396143ce8e462b6460736efdbfd.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 43986 |
| 359 | *f572574e8f466040330510743d57e07ac795ed8caa62856f3efd2bff4f69793d* | .{0,1000}f572574e8f466040330510743d57e07ac795ed8caa62856f3efd2bff4f69793d.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | #filehash | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 44031 | |
| 360 | *f59b24c1d84e1bbb4c0dc2677bb4010b474eb36a62c54ed1fbbf04d05aaf6a22* | .{0,1000}f59b24c1d84e1bbb4c0dc2677bb4010b474eb36a62c54ed1fbbf04d05aaf6a22.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 44043 |
| 361 | *f8ffdb3b2c1b6172387a0e776a6f400c5117a0e525a3456465e3de4614555c10* | .{0,1000}f8ffdb3b2c1b6172387a0e776a6f400c5117a0e525a3456465e3de4614555c10.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 44273 |
| 362 | *faaafe6256f59d72d96a71d7c12dccb964338c7ef8b9dbf359503ccd2ce79e41* | .{0,1000}faaafe6256f59d72d96a71d7c12dccb964338c7ef8b9dbf359503ccd2ce79e41.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 44384 |
| 363 | *fbe18d97dcbd4ee2b6d3d9457142595613cb86a3f59fc7a54f52731925e5026e* | .{0,1000}fbe18d97dcbd4ee2b6d3d9457142595613cb86a3f59fc7a54f52731925e5026e.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #filehash | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 44529 |
| 364 | *fde28cc5a25646c7b2579cd11a6914077500fabb172f8b44fd56bf9cfbad0511* | .{0,1000}fde28cc5a25646c7b2579cd11a6914077500fabb172f8b44fd56bf9cfbad0511.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #filehash | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 44697 |
| 365 | *from pysnaffler.rules.constants import * | .{0,1000}from\spysnaffler\.rules\.constants\simport\s.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 45333 |
| 366 | *from pysnaffler.rules.rule import SnaffleRule* | .{0,1000}from\spysnaffler\.rules\.rule\simport\sSnaffleRule.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 45334 |
| 367 | *from pysnaffler.ruleset import SnafflerRuleSet* | .{0,1000}from\spysnaffler\.ruleset\simport\sSnafflerRuleSet.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 45335 |
| 368 | *from pysnaffler.scanner import SnafflerScanner* | .{0,1000}from\spysnaffler\.scanner\simport\sSnafflerScanner.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 45336 |
| 369 | *from pysnaffler.snaffler import * | .{0,1000}from\spysnaffler\.snaffler\simport\s.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 45337 |
| 370 | *get_dpapi_masterkeys(* | .{0,1000}get_dpapi_masterkeys\(.{0,1000} | offensive_tool_keyword | Carseat | Python implementation of GhostPack Seatbelt situational awareness tool | T1012 - T1082 - T1087 - T1124 - T1217 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/0xthirteen/Carseat | 1 | 0 | #content | N/A | 8 | 3 | 257 | 21 | 2024-11-12T19:37:38Z | 2024-11-08T02:08:53Z | 45631 |
| 371 | *Get-AndDisplayInformation -ClassName "Win32_BIOS"* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_BIOS\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45870 | |
| 372 | *Get-AndDisplayInformation -ClassName "Win32_ComputerSystem" -PropertyFilter UserName* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_ComputerSystem\"\s\-PropertyFilter\sUserName.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45871 | |
| 373 | *Get-AndDisplayInformation -ClassName "Win32_ComputerSystem"* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_ComputerSystem\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45872 | |
| 374 | *Get-AndDisplayInformation -ClassName "Win32_Desktop"* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Desktop\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45873 | |
| 375 | *Get-AndDisplayInformation -ClassName "Win32_LocalTime"* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LocalTime\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45874 | |
| 376 | *Get-AndDisplayInformation -ClassName "Win32_LogicalDisk" -PropertyFilter DeviceID,DriveType,ProviderName,VolumeName,Size,FreeSpace,PSComputerName* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LogicalDisk\"\s\-PropertyFilter\sDeviceID,DriveType,ProviderName,VolumeName,Size,FreeSpace,PSComputerName.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45875 | |
| 377 | *Get-AndDisplayInformation -ClassName "Win32_LogonSession"* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_LogonSession\".{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45876 | |
| 378 | *Get-AndDisplayInformation -ClassName "Win32_OperatingSystem" -PropertyFilter Build*,OSType,ServicePack** | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_OperatingSystem\"\s\-PropertyFilter\sBuild.{0,1000},OSType,ServicePack.{0,1000}.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45877 | |
| 379 | *Get-AndDisplayInformation -ClassName "Win32_OperatingSystem" -PropertyFilter user* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_OperatingSystem\"\s\-PropertyFilter\suser.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45878 | |
| 380 | *Get-AndDisplayInformation -ClassName "Win32_Processor" -PropertyFilter ** | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Processor\"\s\-PropertyFilter\s.{0,1000}.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45879 | |
| 381 | *Get-AndDisplayInformation -ClassName "Win32_QuickFixEngineering" -PropertyFilter HotFixId* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_QuickFixEngineering\"\s\-PropertyFilter\sHotFixId.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45880 | |
| 382 | *Get-AndDisplayInformation -ClassName "Win32_Service" -PropertyFilter Status,Name,DisplayName* | .{0,1000}Get\-AndDisplayInformation\s\-ClassName\s\"Win32_Service\"\s\-PropertyFilter\sStatus,Name,DisplayName.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 45881 | |
| 383 | *Get-VolumeShadowCopy * | .{0,1000}Get\-VolumeShadowCopy\s.{0,1000} | offensive_tool_keyword | Powersploit | PowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of files | T1003 - T1103 - T1213 | TA0006 - TA0009 - TA0010 | N/A | Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46320 |
| 384 | *github.com/SafeJKA/Kidlogger* | .{0,1000}github\.com\/SafeJKA\/Kidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46439 |
| 385 | *graphspy -i * | .{0,1000}graphspy\s\-i\s.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 46693 |
| 386 | *GraphSpy.GraphSpy:main* | .{0,1000}GraphSpy\.GraphSpy\:main.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | #content | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 46694 |
| 387 | *GraphSpy-master.zip* | .{0,1000}GraphSpy\-master\.zip.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 1 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 46695 |
| 388 | *HEHE - YOU HAVE BEEN PWENED* | .{0,1000}HEHE\s\-\sYOU\sHAVE\sBEEN\sPWENED.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 47083 | |
| 389 | *http://pastie.org/p/*/raw* | .{0,1000}http\:\/\/pastie\.org\/p\/.{0,1000}\/raw.{0,1000} | greyware_tool_keyword | pastie.org | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | http://pastie.org/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47503 |
| 390 | *http://temp.sh/*/* | .{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | temp.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47519 |
| 391 | *http://zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd.onion* | .{0,1000}http\:\/\/zerobinftagjpeeebbvyzjcqyjpmjvynj5qlexwyxe7l3vqejxnqv5qd\.onion.{0,1000} | greyware_tool_keyword | zerobin.net | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | https://zerobin.net/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47545 |
| 392 | *https://*.app.github.dev/* | .{0,1000}https\:\/\/.{0,1000}\.app\.github\.dev\/.{0,1000} | greyware_tool_keyword | github | access to a GitHub Codespace environment - Github Codespaces have a public port forwarding option allowing you to make your server available for the public. | T1071 - T1572 | TA0001 - TA0005 | N/A | N/A | Collection | https://detect.fyi/how-threat-actors-use-github-bd991c11ed37 | 0 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 47587 |
| 393 | *https://*.fex.net/download/* | .{0,1000}https\:\/\/.{0,1000}\.fex\.net\/download\/.{0,1000} | greyware_tool_keyword | fex.net | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Collection | https://fex.net | 1 | 1 | #filehostingservice | downloading a file | 10 | 10 | N/A | N/A | N/A | N/A | 47595 |
| 394 | *https://*.trycloudflare.com* | .{0,1000}https\:\/\/.{0,1000}\.trycloudflare\.com.{0,1000} | greyware_tool_keyword | trycloudflare.com | Attackers abuse this service to expose malicious servers on a *.trycloudflare.com subdomain | T1567.002 - T1102 - T1071.001 - T1036 | TA0001 - TA0005 - TA0009 | N/A | N/A | Collection | https://lots-project.com/site/2a2e747279636c6f7564666c6172652e636f6d | 0 | 1 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47617 |
| 395 | *https://0bin.net/paste/*+* | .{0,1000}https\:\/\/0bin\.net\/paste\/.{0,1000}\+.{0,1000} | greyware_tool_keyword | 0bin.net | Accessing a paste on 0bin.net | T1213 - T1190 | TA0001 - TA0009 - TA0010 | N/A | N/A | Collection | https://0bin.net | 1 | 1 | #PastebinLike | N/A | 5 | 10 | N/A | N/A | N/A | N/A | 47631 |
| 396 | *https://1ty.me/* | .{0,1000}https\:\/\/1ty\.me\/.{0,1000} | greyware_tool_keyword | 1ty.me | temporary notes service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | N/A | Collection | https://1ty.me | 1 | 1 | #PastebinLike | downloading or uploading data | 10 | 10 | N/A | N/A | N/A | N/A | 47645 |
| 397 | *https://anonfiles.com/*/* | .{0,1000}https\:\/\/anonfiles\.com\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | anonfiles.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - BitLocker - AvosLocker - Hive - Royal - LockBit - Vice Society - Conti - RansomHub | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47653 |
| 398 | *https://bayfiles.com/* | .{0,1000}https\:\/\/bayfiles\.com\/.{0,1000} | greyware_tool_keyword | bayfiles | hosting site abused by attackers - blocked site in a lot of countries | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | CyClops | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47684 |
| 399 | *https://bitbucket.org/*/downloads/*.bat* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47688 |
| 400 | *https://bitbucket.org/*/downloads/*.dll* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47689 |
| 401 | *https://bitbucket.org/*/downloads/*.dll* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47690 |
| 402 | *https://bitbucket.org/*/downloads/*.exe* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47691 |
| 403 | *https://bitbucket.org/*/downloads/*.ps1* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47692 |
| 404 | *https://bitbucket.org/*/downloads/*.rar* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47693 |
| 405 | *https://bitbucket.org/*/downloads/*.zip* | .{0,1000}https\:\/\/bitbucket\.org\/.{0,1000}\/downloads\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | bitbucket.org | legitimate hosting platform abused by malwares like lummastealer | T1213 - T1102 | TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | #filehostingservice | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 47694 |
| 406 | *https://dropmefiles.com/* | .{0,1000}https\:\/\/dropmefiles\.com\/.{0,1000} | greyware_tool_keyword | dropmefiles.com | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Mallox - Dispossessor - BitLocker - Black Basta - Hive - Royal - LockBit - Vice Society | Collection | https://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Mallox/20230427.json#L286C25-L286C48 | 1 | 1 | #filehostingservice | downloading files url | 8 | 6 | 504 | 51 | 2025-04-19T17:43:15Z | 2023-05-02T16:17:48Z | 47749 |
| 407 | *https://easyupload.io/* | .{0,1000}https\:\/\/easyupload\.io\/.{0,1000} | greyware_tool_keyword | easyupload.io | file hosting platform abused by attackers to host malicious - url used when downloading a file on the site | T1567.002 - T1071.001 - T1041 - T1036.002 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 47751 |
| 408 | *https://file.io/* | .{0,1000}https\:\/\/file\.io\/.{0,1000} | greyware_tool_keyword | file.io | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | BlackCat - Black Basta - Akira - AvosLocker - Hive - Ragnar Locker - Royal - LockBit - Vice Society - Conti | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47761 |
| 409 | *https://filebin.net/* | .{0,1000}https\:\/\/filebin\.net\/.{0,1000} | greyware_tool_keyword | filebin.net | file hosting platform abused by attackers to host malicious file - raw access and api available | T1119 | TA0009 - TA0010 | N/A | N/A | Collection | https://filebin.net | 1 | 1 | #filehostingservice | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47763 |
| 410 | *https://files.catbox.moe/* | https:\/\/files\.catbox\.moe\/[^\s\n]+ | greyware_tool_keyword | catbox.moe | The cutest free file host you've ever seen - abused by threat actors | T1560.001 - T1190 - T1102 - T1027.002 | TA0001 - TA0005 - TA0042 | N/A | N/A | Collection | https://files[.]catbox.moe | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47764 |
| 411 | *https://media.discordapp.net/attachments/*.bat* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47821 |
| 412 | *https://media.discordapp.net/attachments/*.exe* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47822 |
| 413 | *https://media.discordapp.net/attachments/*.hta* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47823 |
| 414 | *https://media.discordapp.net/attachments/*.iso* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47824 |
| 415 | *https://media.discordapp.net/attachments/*.jar* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47825 |
| 416 | *https://media.discordapp.net/attachments/*.msi* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47826 |
| 417 | *https://media.discordapp.net/attachments/*.py* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.py.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47827 |
| 418 | *https://media.discordapp.net/attachments/*.vbs* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47828 |
| 419 | *https://media.discordapp.net/attachments/*.zip* | .{0,1000}https\:\/\/media\.discordapp\.net\/attachments\/.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | discord | Downloading discord executables and archives attachments | T1189 | TA0001 - TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 6 | 9 | N/A | N/A | N/A | N/A | 47829 |
| 420 | *https://mega.nz/file/* | .{0,1000}https\:\/\/mega\.nz\/file\/.{0,1000} | greyware_tool_keyword | mega.nz | Direct file download links on Mega.nz - file sharing activity often abused by attackers for Collection | T1105 - T1114 - T1083 | TA0009 | N/A | Akira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice #P2P | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47832 |
| 421 | *https://mega.nz/folder/* | .{0,1000}https\:\/\/mega\.nz\/folder\/.{0,1000} | greyware_tool_keyword | mega.nz | Direct folder sharing links on Mega.nz for accessing multiple files - file sharing activity often abused by attackers for Collection | T1105 - T1114 - T1083 | TA0009 | N/A | Akira - Conti - mount-locker - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - MONTI - DarkSide - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice #P2P | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47833 |
| 422 | *https://privnote.com/* | .{0,1000}https\:\/\/privnote\.com\/.{0,1000} | greyware_tool_keyword | privnote.com | temporary notes service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Akira - Black Basta | Collection | https://github.com/Casualtek/Ransomchats/blob/4a25ac6ad165a4e600aeb72718c3ad41e8f6ce3a/Akira/20240620.json#L31C27-L31C48 | 1 | 1 | #PastebinLike | downloading files url | 5 | 6 | 504 | 51 | 2025-04-19T17:43:15Z | 2023-05-02T16:17:48Z | 47878 |
| 423 | *https://put.io/default/magnet?url=* | .{0,1000}https\:\/\/put\.io\/default\/magnet\?url\=.{0,1000} | greyware_tool_keyword | put.io | A storage and torrenting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | Scattered Spider - RagnarLocker - Medusa | Collection | https://put.i | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47883 |
| 424 | *https://qaz.im/load/* | .{0,1000}https\:\/\/qaz\.im\/load\/.{0,1000} | greyware_tool_keyword | qaz.im | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.im/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47890 |
| 425 | *https://qaz.im/zaq/* | .{0,1000}https\:\/\/qaz\.im\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.im | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.im/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47891 |
| 426 | *https://qaz.is/load/* | .{0,1000}https\:\/\/qaz\.is\/load\/.{0,1000} | greyware_tool_keyword | qaz.is | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.is/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47893 |
| 427 | *https://qaz.is/zaq/* | .{0,1000}https\:\/\/qaz\.is\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.is | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.is/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47894 |
| 428 | *https://qaz.su/load/* | .{0,1000}https\:\/\/qaz\.su\/load\/.{0,1000} | greyware_tool_keyword | qaz.su | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.su/ | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47896 |
| 429 | *https://qaz.su/zaq/* | .{0,1000}https\:\/\/qaz\.su\/zaq\/.{0,1000} | greyware_tool_keyword | qaz.su | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker - Black Basta | Collection | https://qaz.su/ | 1 | 1 | #filehostingservice | downloading notes url | 10 | 10 | N/A | N/A | N/A | N/A | 47897 |
| 430 | *https://qu.ax/*.* | https\:\/\/qu\.ax\/[^\s\n]+ | greyware_tool_keyword | qu.ax | qu.ax is a quick and private file hosting service - abused by threat actors | T1560.001 - T1190 - T1102 - T1027.002 | TA0001 - TA0005 - TA0042 | N/A | N/A | Collection | https://qu[.]ax/ | 1 | 1 | #filehostingservice | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 47898 |
| 431 | *https://rentry.co/* | .{0,1000}https\:\/\/rentry\.co\/.{0,1000} | greyware_tool_keyword | rentry.co | accessing a pastebinlike site - often abused by malware | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 5 | 8 | N/A | N/A | N/A | N/A | 47912 |
| 432 | *https://rentry.co/*/raw* | .{0,1000}https\:\/\/rentry\.co\/.{0,1000}\/raw.{0,1000} | greyware_tool_keyword | rentry.co | raw format paste access attempt - abused by attackers to store malicious payloads | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47913 |
| 433 | *https://rentry.co/cdn-cgi/challenge-platform/* | .{0,1000}https\:\/\/rentry\.co\/cdn\-cgi\/challenge\-platform\/.{0,1000} | greyware_tool_keyword | rentry.co | raw format paste access attempt - abused by attackers to store malicious payloads | T1105 - T1114 - T1083 | TA0009 | N/A | N/A | Collection | N/A | 1 | 1 | #PastebinLike | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 47914 |
| 434 | *https://s3.filebin.net/filebin/* | .{0,1000}https\:\/\/s3\.filebin\.net\/filebin\/.{0,1000} | greyware_tool_keyword | filebin.net | file hosting platform abused by attackers to host malicious file - raw access and api available | T1119 | TA0009 | N/A | N/A | Collection | https://filebin.net | 1 | 1 | #filehostingservice | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47917 |
| 435 | *https://send.exploit.in/api/download* | .{0,1000}https\:\/\/send\.exploit\.in\/api\/download.{0,1000} | greyware_tool_keyword | send.exploit.in | downloading files - hosting service frequently exploited by attackers - should be blocked | T1567 - T1071 - T1020 - T1005 | TA0010 - TA0009 | N/A | LockBit - Hive - Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47921 |
| 436 | *https://share.riseup.net/2* | .{0,1000}https\:\/\/share\.riseup\.net\/2.{0,1000} | greyware_tool_keyword | share.riseup.net | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | AvosLocker | Collection | https://share.riseup.net | 1 | 1 | #filehostingservice | downloading files url | 10 | 10 | N/A | N/A | N/A | N/A | 47925 |
| 437 | *https://steamcommunity.com/profiles/* | .{0,1000}https\:\/\/steamcommunity\.com\/profiles\/.{0,1000} | greyware_tool_keyword | steam | Steam profiles have been leveraged to host payload addresses for malware delivery - making them a potential threat vector in corporate environments. This tactic can serve as a valuable hunting tip for threat detection efforts | T1102 - T1091 - T1204 | TA0001 - TA0009 | Lumma Stealer | N/A | Collection | N/A | 0 | 1 | N/A | N/A | 1 | 1 | N/A | N/A | N/A | N/A | 47941 |
| 438 | *https://temp.sh/*/* | .{0,1000}https\:\/\/temp\.sh\/.{0,1000}\/.{0,1000} | greyware_tool_keyword | temp.sh | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Black Basta | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47955 |
| 439 | *https://tempsend.com/* | .{0,1000}https\:\/\/tempsend\.com\/.{0,1000} | greyware_tool_keyword | tempsend.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47957 |
| 440 | *https://termbin.com/test* | .{0,1000}https\:\/\/termbin\.com\/test.{0,1000} | greyware_tool_keyword | termbin.com | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | termbin.com | 1 | 1 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 47959 |
| 441 | *https://textbin.net/raw/* | .{0,1000}https\:\/\/textbin\.net\/raw\/.{0,1000} | greyware_tool_keyword | textbin.net | textbin.net raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | textbin.net | 1 | 1 | #PastebinLike | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47960 |
| 442 | *https://tmpfiles.org/dl/*.exe* | .{0,1000}https\:\/\/tmpfiles\.org\/dl\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | tmpfiles.org | download of an executable files from tmpfiles.org often used by ransomware groups | T1566.002 - T1192 - T1105 | TA0001 - TA0002 | N/A | N/A | Collection | N/A | 1 | 1 | #filehostingservice | greyware tool - risk of false positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 47963 |
| 443 | *https://transfer.sh/get/*/*.pdf* | .{0,1000}https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.pdf.{0,1000} | offensive_tool_keyword | transfer.sh | Downloading pdf from transfer.sh | T1105 - T1204 - T1071 - T1195 | TA0002 - TA0005 - TA0006 | N/A | Black Basta | Collection | https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375 | 1 | 1 | #filehostingservice | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 47968 |
| 444 | *https://transfer.sh/get/*/*.py* | https\:\/\/transfer\.sh\/get\/.{0,1000}\/.{0,1000}\.py.{0,1000} | offensive_tool_keyword | transfer.sh | Downloading python scripts from transfer.sh | T1105 - T1204 - T1071 - T1195 | TA0002 - TA0005 - TA0006 | N/A | Black Basta | Collection | https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375 | 1 | 1 | #filehostingservice | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 47969 |
| 445 | *https://transfert-my-files.com/files/* | .{0,1000}https\:\/\/transfert\-my\-files\.com\/files\/.{0,1000} | greyware_tool_keyword | transfert-my-files.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | N/A | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 47970 |
| 446 | *https://ufile.io/* | .{0,1000}https\:\/\/ufile\.io\/.{0,1000} | greyware_tool_keyword | ufile.io | temporary file hosting service - abused by attackers to share informations with their victims | T1105 - T1071 | TA0010 - TA0009 | N/A | Hive | Collection | https://ufile.io | 1 | 1 | N/A | downloading files url | 5 | 6 | N/A | N/A | N/A | N/A | 47978 |
| 447 | *https://www.4shared.com/get/* | .{0,1000}https\:\/\/www\.4shared\.com\/get\/.{0,1000} | greyware_tool_keyword | 4shared.com | Downloading a file from 4shared.com | T1105 - T1071 - T1125 | TA0009 | N/A | Turla | Collection | 4shared.com | 1 | 1 | #filehostingservice | N/A | 6 | 5 | N/A | N/A | N/A | N/A | 47998 |
| 448 | *https://www.mediafire.com/api/*/folder/get_content.php* | .{0,1000}https\:\/\/www\.mediafire\.com\/api\/.{0,1000}\/folder\/get_content\.php.{0,1000} | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1114 - T1083 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 48014 |
| 449 | *https://www.nirsoft.net/toolsdownload/* | .{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000} | greyware_tool_keyword | nirsoft tools | NirSoft is a legitimate software company that develops system utilities for Windows. Some of its tools can be used by malicious actors to recover passwords harvest sensitive information and conduct password attacks. | T1003 - T1003.001 - T1003.002 - T1110 - T1566 | TA0002 - TA0003 - TA0004 - TA0006 - TA0007 - TA0008 - TA0011 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48016 |
| 450 | *https://www.nirsoft.net/utils/webcamimagesave.zip* | https\:\/\/www\.nirsoft\.net\/utils\/webcamimagesave\.zip | offensive_tool_keyword | nirsoft | designed to capture webcam images | T1125 - T1056.004 - T1140 | TA0005 - TA0006 | N/A | N/A | Collection | https://medium.com/checkmarx-security/python-obfuscation-traps-1acced941375 | 1 | 1 | N/A | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 48021 |
| 451 | *https://www.premiumize.me/* | .{0,1000}https\:\/\/www\.premiumize\.me\/.{0,1000} | greyware_tool_keyword | premiumize.me | hosting service abused by attackers | T1583.003 - T1071 - T1102 | TA0010 - TA0005 - TA0009 | N/A | N/A | Collection | www.premiumize.me | 1 | 1 | #filehostingservice #P2P | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 48022 |
| 452 | *https://www.sendspace.com/delete* | .{0,1000}https\:\/\/www\.sendspace\.com\/delete.{0,1000} | greyware_tool_keyword | sendspace.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Dispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice Society | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48023 |
| 453 | *https://www.sendspace.com/file/* | .{0,1000}\shttps\:\/\/www\.sendspace\.com\/file\/.{0,1000} | greyware_tool_keyword | sendspace.com | Interesting observation on the file-sharing platform preferences derived from the negotiations chats with LockBit victims | T1567 - T1022 - T1074 - T1105 | TA0011 - TA0009 - TA0010 - TA0008 | N/A | Dispossessor - Black Basta - Hive - Ragnar Locker - Royal - LockBit - Vice Society | Collection | https://twitter.com/mthcht/status/1660953897622544384 | 1 | 1 | #filehostingservice | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 48024 |
| 454 | *https://www.telerik.com/download/fiddler/* | .{0,1000}https\:\/\/www\.telerik\.com\/download\/fiddler\/.{0,1000} | greyware_tool_keyword | fiddler | fiddler - capture https requests | T1056 - T1040 - T1557 | TA0009 - TA00010 | N/A | N/A | Collection | https://www.telerik.com/ | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 48032 |
| 455 | *https://zerobin.net/?* | .{0,1000}https\:\/\/zerobin\.net\/\?.{0,1000} | greyware_tool_keyword | zerobin.net | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | https://zerobin.net/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 48041 |
| 456 | *IEX(New-Object System.Net.WebClient).DownloadString("https://raw.githubusercontent.com/* | .{0,1000}IEX\(New\-Object\sSystem\.Net\.WebClient\)\.DownloadString\(\"https\:\/\/raw\.githubusercontent\.com\/.{0,1000} | greyware_tool_keyword | powershell | download from github from memory | T1105 - T1059.001 - T1204 | TA0009 - TA0002 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 48209 |
| 457 | *IEX*nopaste.net* | .{0,1000}IEX.{0,1000}nopaste\.net.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Collection | https://www.shellhub.io/ | 1 | 0 | #Pastebinlike #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 48210 |
| 458 | *imaohw/nib/rsu/* | .{0,1000}imaohw\/nib\/rsu\/.{0,1000} | offensive_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0006 - TA0007 | N/A | Black Basta | Collection | N/A | 1 | 0 | N/A | N/A | N/A | 10 | N/A | N/A | N/A | N/A | 48237 |
| 459 | *InvokeReflectivePEInjection* | .{0,1000}InvokeReflectivePEInjection.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 49412 | |
| 460 | *Invoke-ReflectivePEInjection* | .{0,1000}Invoke\-ReflectivePEInjection.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 49415 | |
| 461 | *IWR*nopaste.net* | .{0,1000}IWR.{0,1000}nopaste\.net.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Collection | https://www.shellhub.io/ | 1 | 0 | #Pastebinlike #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 49983 |
| 462 | *kerberos::golden *.kirbi* | .{0,1000}kerberos\:\:golden\s.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 50326 | |
| 463 | *KidLogger-*.dmg* | .{0,1000}KidLogger\-.{0,1000}\.dmg.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | #macos | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50446 |
| 464 | *kidlogger.conf* | .{0,1000}kidlogger\.conf.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50447 |
| 465 | *Kidlogger.exe* | .{0,1000}Kidlogger\.exe.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50448 |
| 466 | *KidLogger.lnk* | .{0,1000}KidLogger\.lnk.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50449 |
| 467 | *KidLogger.net* | .{0,1000}KidLogger\.net.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50450 |
| 468 | *KidLogger.pif* | .{0,1000}KidLogger\.pif.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50451 |
| 469 | *KidLogger.url* | .{0,1000}KidLogger\.url.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50452 |
| 470 | *kidlogger_install* | .{0,1000}kidlogger_install.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50453 |
| 471 | *kidlogger_user.exe* | .{0,1000}kidlogger_user\.exe.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 50454 |
| 472 | *L3Vzci9iaW4vd2hvYW1p* | .{0,1000}L3Vzci9iaW4vd2hvYW1p.{0,1000} | offensive_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0006 - TA0007 | N/A | Black Basta | Collection | N/A | 1 | 0 | N/A | N/A | N/A | 10 | N/A | N/A | N/A | N/A | 50681 |
| 473 | *lanscan_arp.py* | .{0,1000}lanscan_arp\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 50789 |
| 474 | *make shared dir for kidlogger ini files* | .{0,1000}make\sshared\sdir\sfor\skidlogger\sini\sfiles.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51565 |
| 475 | *MpCmdRun.exe -DownloadFile -url http://*.exe -path * | .{0,1000}MpCmdRun\.exe\s\-DownloadFile\s\-url\shttp\:\/\/.{0,1000}\.exe\s\-path\s.{0,1000} | greyware_tool_keyword | MpCmdRun | MpCmdRun LOLBAS exploitation observed used by threat actors | T1105 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 52307 |
| 476 | *mshta https://tinyurl.com/* | .{0,1000}mshta\shttps\:\/\/tinyurl\.com\/.{0,1000} | greyware_tool_keyword | mshta | downloading from tinyurl | T1204.002 - T1105 - T1071.001 - T1102.003 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 52402 |
| 477 | *mshta javascript:a=(GetObject("script:http*.sct*)).Exec();close();* | .{0,1000}mshta\sjavascript\:a\=\(GetObject\(\"script\:http.{0,1000}\.sct.{0,1000}\)\)\.Exec\(\)\;close\(\)\;.{0,1000} | greyware_tool_keyword | mshta | Invoking a scriptlet file hosted remotely | T1218.005 - T1059.001 - T1105 | TA0002 - TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 52404 |
| 478 | *mshta.exe https://tinyurl.com/* | .{0,1000}mshta\.exe\shttps\:\/\/tinyurl\.com\/.{0,1000} | greyware_tool_keyword | mshta | downloading from tinyurl | T1204.002 - T1105 - T1071.001 - T1102.003 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 52407 |
| 479 | *mshta.exe javascript:a=(GetObject("script:http*.sct*)).Exec();close();* | .{0,1000}mshta\.exe\sjavascript\:a\=\(GetObject\(\"script\:http.{0,1000}\.sct.{0,1000}\)\)\.Exec\(\)\;close\(\)\;.{0,1000} | greyware_tool_keyword | mshta | Invoking a scriptlet file hosted remotely | T1218.005 - T1059.001 - T1105 | TA0002 - TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 52408 |
| 480 | *New-VolumeShadowCopy -Volume C:\* | .{0,1000}New\-VolumeShadowCopy\s\-Volume\sC\:\\.{0,1000} | offensive_tool_keyword | Powersploit | PowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of files | T1003 - T1103 - T1213 | TA0006 - TA0009 - TA0010 | N/A | Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 53314 |
| 481 | *nmap_port_scanner.py* | .{0,1000}nmap_port_scanner\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 53478 |
| 482 | *nmap_port_scanner_ip_obj.py* | .{0,1000}nmap_port_scanner_ip_obj\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 53479 |
| 483 | *nopaste.net*IWR* | .{0,1000}nopaste\.net.{0,1000}IWR.{0,1000} | greyware_tool_keyword | nopaste.net | nopaste.net is a temporary file host - nopaste and clipboard across machines. You can upload files or text and share the link with others - abused by attackers for collection and data exfiltration | T1567.002 - T1036.005 - T1102 - T1071.001 | TA0005 - TA0009 - TA0010 | N/A | N/A | Collection | https://www.shellhub.io/ | 1 | 0 | #Pastebinlike #filehostingservice | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 53543 |
| 484 | *Nothing was logged into the temp workingKeyLog!* | .{0,1000}Nothing\swas\slogged\sinto\sthe\stemp\sworkingKeyLog!.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 53575 |
| 485 | *objects.githubusercontent.com/github-production-release-asset-* | .{0,1000}objects\.githubusercontent\.com\/github\-production\-release\-asset\-.{0,1000} | greyware_tool_keyword | github | Github executables download initiated - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 53821 |
| 486 | *package kidlogger* | .{0,1000}package\skidlogger.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 54340 |
| 487 | *paste.ee/d/* | .{0,1000}paste\.ee\/d\/.{0,1000} | greyware_tool_keyword | paste.ee | fetching data from paste.ee | T1041 | TA0009 | N/A | N/A | Collection | paste.ee | 1 | 1 | #PastebinLike | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 54489 |
| 488 | *pastebin.com*/raw/* | .{0,1000}pastebin\.com.{0,1000}\/raw\/.{0,1000}\s | greyware_tool_keyword | pastebin | pastebin raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | Redline Stealer | Black Basta | Collection | pastebin.com | 1 | 1 | #PastebinLike | greyware tool - risks of False positive ! | 8 | 10 | N/A | N/A | N/A | N/A | 54491 |
| 489 | *pastebin.com*/rw/* | .{0,1000}pastebin\.com.{0,1000}\/rw\/.{0,1000} | greyware_tool_keyword | pastebin | pastebin raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | Redline Stealer | Black Basta | Collection | pastebin.com | 1 | 1 | #PastebinLike | greyware tool - risks of False positive ! | 8 | 10 | N/A | N/A | N/A | N/A | 54492 |
| 490 | *pastebin.pl/view/raw/* | .{0,1000}pastebin\.pl\/view\/raw\/.{0,1000} | greyware_tool_keyword | pastebin.pl | accessing paste raw content | T1119 | TA0009 | N/A | N/A | Collection | https://pastebin.pl/ | 1 | 1 | #PastebinLike | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 54495 |
| 491 | *Payload-Generator/trix-back-gen.zip* | .{0,1000}Payload\-Generator\/trix\-back\-gen\.zip.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 1 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 54549 | |
| 492 | *pipx install graphspy* | .{0,1000}pipx\sinstall\sgraphspy.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 54895 |
| 493 | *pipx upgrade graphspy* | .{0,1000}pipx\supgrade\sgraphspy.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 0 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 54897 |
| 494 | *port_scanner_ip_obj.py* | .{0,1000}port_scanner_ip_obj\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 55023 |
| 495 | *port_scanner_regex.py* | .{0,1000}port_scanner_regex\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 55024 |
| 496 | *powershell.exe curl http://[0-9]{1,3}* | .{0,1000}powershell.+curl\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000} | greyware_tool_keyword | powershell | downloading from IP without domain name | T1105 | TA0009 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html | 1 | 0 | N/A | only the regex part matters | 6 | 10 | N/A | N/A | N/A | N/A | 55216 |
| 497 | *powershell.exe Invoke-WebRequest http://[0-9]{1,3}* | .{0,1000}powershell\.exe\s+Invoke\-WebRequest\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000} | greyware_tool_keyword | powershell | downloading from IP without domain name | T1105 | TA0009 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html | 1 | 0 | N/A | only the regex part matters | 6 | 10 | N/A | N/A | N/A | N/A | 55221 |
| 498 | *powershell.exe iwr http://[0-9]{1,3}* | .{0,1000}powershell\.exe\s+iwr\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000} | greyware_tool_keyword | powershell | downloading from IP without domain name | T1105 | TA0009 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html | 1 | 0 | N/A | only the regex part matters | 6 | 10 | N/A | N/A | N/A | N/A | 55222 |
| 499 | *powershell.exe -nop -c "start-job *Import-Module BitsTransfer*$env:temp*GetRandomFileName()*Start-BitsTransfer -Source 'http*Remove-Item*Receive-Job* | powershell\.exe\s\-nop\s\-c\s\"start\-job\s.{0,1000}Import\-Module\sBitsTransfer.{0,1000}\$env\:temp.{0,1000}GetRandomFileName\(\).{0,1000}Start\-BitsTransfer\s\-Source\s\'http.{0,1000}Remove\-Item.{0,1000}Receive\-Job.{0,1000} | offensive_tool_keyword | powershell | deployment of a payload through a PowerShell stager using bits to download | T1197 | TA0009 | N/A | N/A | Collection | https://thedfirreport.com/2023/09/25/from-screenconnect-to-hive-ransomware-in-61-hours/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 55229 |
| 500 | *powershell.exe -nop -w hidden -c "IEX ((new-object net.webclient).downloadstring('http://[0-9]{1,3}* | .{0,1000}powershell.+\s-nop\s-w\shidden\s-c\s\"IEX\s\(\(new\-object net\.webclient\)\.downloadstring\(\'http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000} | greyware_tool_keyword | powershell | downloading from IP without domain name | T1105 | TA0009 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html | 1 | 0 | N/A | only the regex part matters | 6 | 10 | N/A | N/A | N/A | N/A | 55237 |
| 501 | *powershell.exe wget http://[0-9]{1,3}* | .{0,1000}powershell\.exe\s+wget\s+http:\/\/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}(\/|\:).{0,1000} | greyware_tool_keyword | powershell | downloading from IP without domain name | T1105 | TA0009 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html | 1 | 0 | N/A | only the regex part matters | 6 | 10 | N/A | N/A | N/A | N/A | 55241 |
| 502 | *PowerShell/Turla.T* | .{0,1000}PowerShell\/Turla\.T.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 55247 | |
| 503 | *pysnaffler -* | .{0,1000}pysnaffler\s\-.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56038 |
| 504 | *pysnaffler 'smb2+kerberos+password:* | .{0,1000}pysnaffler\s\'smb2\+kerberos\+password\:.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56039 |
| 505 | *pysnaffler 'smb2+ntlm-nt://* | .{0,1000}pysnaffler\s\'smb2\+ntlm\-nt\:\/\/.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56040 |
| 506 | *pysnaffler 'smb2+ntlm-password://* | .{0,1000}pysnaffler\s\'smb2\+ntlm\-password\:\/\/.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56041 |
| 507 | *pysnaffler.whatif:main* | .{0,1000}pysnaffler\.whatif\:main.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56042 |
| 508 | *pysnaffler/_version.py* | .{0,1000}pysnaffler\/_version\.py.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 0 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56043 |
| 509 | *pysnaffler-main* | .{0,1000}pysnaffler\-main.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 1 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 56044 |
| 510 | *raw.githubusercontent.com*.7z* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.7z.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56304 |
| 511 | *raw.githubusercontent.com*.apk* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.apk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56305 |
| 512 | *raw.githubusercontent.com*.app* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.app.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56306 |
| 513 | *raw.githubusercontent.com*.as* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.as.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56307 |
| 514 | *raw.githubusercontent.com*.asc* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.asc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56308 |
| 515 | *raw.githubusercontent.com*.asp* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.asp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56309 |
| 516 | *raw.githubusercontent.com*.bash* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.bash.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | #linux | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56310 |
| 517 | *raw.githubusercontent.com*.bat* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.bat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56311 |
| 518 | *raw.githubusercontent.com*.beacon* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.beacon.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56312 |
| 519 | *raw.githubusercontent.com*.bin* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.bin.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56313 |
| 520 | *raw.githubusercontent.com*.bpl* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.bpl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56314 |
| 521 | *raw.githubusercontent.com*.c | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.c | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56315 |
| 522 | *raw.githubusercontent.com*.cer* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.cer.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56316 |
| 523 | *raw.githubusercontent.com*.cmd* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.cmd.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56317 |
| 524 | *raw.githubusercontent.com*.com* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.com.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56318 |
| 525 | *raw.githubusercontent.com*.cpp* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.cpp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56319 |
| 526 | *raw.githubusercontent.com*.crt* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.crt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56320 |
| 527 | *raw.githubusercontent.com*.cs* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.cs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56321 |
| 528 | *raw.githubusercontent.com*.csh* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.csh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56322 |
| 529 | *raw.githubusercontent.com*.dat* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56323 |
| 530 | *raw.githubusercontent.com*.dll* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.dll.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56324 |
| 531 | *raw.githubusercontent.com*.docm* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.docm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56325 |
| 532 | *raw.githubusercontent.com*.dos* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.dos.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56326 |
| 533 | *raw.githubusercontent.com*.exe* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56327 |
| 534 | *raw.githubusercontent.com*.go* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.go.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56328 |
| 535 | *raw.githubusercontent.com*.gz* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.gz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56329 |
| 536 | *raw.githubusercontent.com*.hta* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.hta.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56330 |
| 537 | *raw.githubusercontent.com*.iso* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.iso.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56331 |
| 538 | *raw.githubusercontent.com*.jar* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56332 |
| 539 | *raw.githubusercontent.com*.js* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.js.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56333 |
| 540 | *raw.githubusercontent.com*.lnk* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.lnk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56334 |
| 541 | *raw.githubusercontent.com*.log* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.log.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56335 |
| 542 | *raw.githubusercontent.com*.mac* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.mac.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56336 |
| 543 | *raw.githubusercontent.com*.mam* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.mam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56337 |
| 544 | *raw.githubusercontent.com*.msi* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.msi.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56338 |
| 545 | *raw.githubusercontent.com*.msp* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.msp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56339 |
| 546 | *raw.githubusercontent.com*.nexe* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.nexe.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56340 |
| 547 | *raw.githubusercontent.com*.nim* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.nim.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56341 |
| 548 | *raw.githubusercontent.com*.otm* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.otm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56342 |
| 549 | *raw.githubusercontent.com*.out* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.out.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56343 |
| 550 | *raw.githubusercontent.com*.ova* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.ova.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56344 |
| 551 | *raw.githubusercontent.com*.pem* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pem.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56345 |
| 552 | *raw.githubusercontent.com*.pfx* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pfx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56346 |
| 553 | *raw.githubusercontent.com*.pl* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pl.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56347 |
| 554 | *raw.githubusercontent.com*.plx* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.plx.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56348 |
| 555 | *raw.githubusercontent.com*.pm* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56349 |
| 556 | *raw.githubusercontent.com*.ppk* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.ppk.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56350 |
| 557 | *raw.githubusercontent.com*.ps1* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.ps1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56351 |
| 558 | *raw.githubusercontent.com*.psm1* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.psm1.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56352 |
| 559 | *raw.githubusercontent.com*.pub* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pub.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56353 |
| 560 | *raw.githubusercontent.com*.py* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.py.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56354 |
| 561 | *raw.githubusercontent.com*.pyc* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pyc.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56355 |
| 562 | *raw.githubusercontent.com*.pyo* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.pyo.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56356 |
| 563 | *raw.githubusercontent.com*.rar* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.rar.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56357 |
| 564 | *raw.githubusercontent.com*.raw* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.raw.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56358 |
| 565 | *raw.githubusercontent.com*.reg* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.reg.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56359 |
| 566 | *raw.githubusercontent.com*.rgs* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.rgs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56360 |
| 567 | *raw.githubusercontent.com*.RGS* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.RGS.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56361 |
| 568 | *raw.githubusercontent.com*.run* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.run.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56362 |
| 569 | *raw.githubusercontent.com*.scpt* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.scpt.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56363 |
| 570 | *raw.githubusercontent.com*.script* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.script.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56364 |
| 571 | *raw.githubusercontent.com*.sct* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.sct.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56365 |
| 572 | *raw.githubusercontent.com*.sh* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.sh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56366 |
| 573 | *raw.githubusercontent.com*.ssh* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.ssh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56367 |
| 574 | *raw.githubusercontent.com*.sys* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.sys.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56368 |
| 575 | *raw.githubusercontent.com*.teamserver* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.teamserver.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56369 |
| 576 | *raw.githubusercontent.com*.temp* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.temp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56370 |
| 577 | *raw.githubusercontent.com*.tgz* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.tgz.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56371 |
| 578 | *raw.githubusercontent.com*.tmp* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.tmp.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56372 |
| 579 | *raw.githubusercontent.com*.vb* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.vb.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56373 |
| 580 | *raw.githubusercontent.com*.vbs* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.vbs.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56374 |
| 581 | *raw.githubusercontent.com*.vbscript* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.vbscript.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56375 |
| 582 | *raw.githubusercontent.com*.ws* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.ws.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56376 |
| 583 | *raw.githubusercontent.com*.wsf* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.wsf.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56377 |
| 584 | *raw.githubusercontent.com*.wsh* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.wsh.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56378 |
| 585 | *raw.githubusercontent.com*.X86* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.X86.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56379 |
| 586 | *raw.githubusercontent.com*.X86_64* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.X86_64.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56380 |
| 587 | *raw.githubusercontent.com*.xlam* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlam.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56381 |
| 588 | *raw.githubusercontent.com*.xlm* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56382 |
| 589 | *raw.githubusercontent.com*.xlsm* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.xlsm.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56383 |
| 590 | *raw.githubusercontent.com*.zip* | .{0,1000}raw\.githubusercontent\.com.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | github | Github raw access content - abused by malwares to retrieve payloads | T1119 | TA0009 | N/A | N/A | Collection | https://github.com/ | 1 | 1 | N/A | greyware tool - risks of False positive ! | 9 | 10 | N/A | N/A | N/A | N/A | 56384 |
| 591 | *RedByte1337/GraphSpy* | .{0,1000}RedByte1337\/GraphSpy.{0,1000} | offensive_tool_keyword | GraphSpy | Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI | T1078.004 - T1110.003 - T1071.001 - T1566.002 - T1656 | TA0001 - TA0006 - TA0003 - TA0005 - TA0008 | N/A | N/A | Collection | https://github.com/RedByte1337/GraphSpy | 1 | 1 | N/A | N/A | 10 | 7 | 680 | 72 | 2025-04-15T21:07:15Z | 2024-02-07T19:47:15Z | 56544 |
| 592 | *reg save hklm\sam *.dat* | .{0,1000}reg\ssave\shklm\\sam\s.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive hklm\sam to a .dat file | T1003.002 - T1564.001 | TA0006 - TA0010 | N/A | Volt Typhoon | Collection | https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56835 |
| 593 | *reg save HKLM\SAM *c:* | .{0,1000}reg\ssave\sHKLM\\SAM\s.{0,1000}c\:.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56836 |
| 594 | *reg save hklm\sam sam* | .{0,1000}reg\ssave\shklm\\sam\ssam.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56838 |
| 595 | *reg save HKLM\SECURITY * | .{0,1000}reg\ssave\sHKLM\\SECURITY\s.{0,1000}c\:.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive hklm\security to a .dat file | T1005 - T1003.002 | TA0005 - TA0003 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56839 |
| 596 | *reg save hklm\system *.dat* | .{0,1000}reg\ssave\shklm\\system\s.{0,1000}\.dat.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive hklm\system to a .dat file | T1005 - T1003.002 | TA0005 - TA0003 | N/A | Volt Typhoon | Collection | https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56840 |
| 597 | *reg save HKLM\SYSTEM *c:* | .{0,1000}reg\ssave\sHKLM\\SYSTEM\s.{0,1000}c\:.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 56841 |
| 598 | *reg save hklm\system system* | .{0,1000}reg\ssave\shklm\\system\ssystem.{0,1000} | greyware_tool_keyword | reg | the commands are used to export the SAM and SYSTEM registry hives which contain sensitive Windows security data including hashed passwords for local accounts. By obtaining these hives an attacker can attempt to crack the hashes or use them in pass-the-hash attacks for unauthorized access. | T1003.002 | TA0009 | N/A | Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 56843 |
| 599 | *reg.exe save hklm\sam * | .{0,1000}reg\.exe\ssave\shklm\\sam\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56862 |
| 600 | *reg.exe save hklm\security * | .{0,1000}reg\.exe\ssave\shklm\\security\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56865 |
| 601 | *reg.exe save hklm\system * | .{0,1000}reg\.exe\ssave\shklm\\system\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56868 |
| 602 | *reg.exe" save hklm\sam * | .{0,1000}reg\.exe\"\ssave\shklm\\sam\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56875 |
| 603 | *reg.exe" save hklm\security * | .{0,1000}reg\.exe\"\ssave\shklm\\security\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56876 |
| 604 | *reg.exe" save hklm\system * | .{0,1000}reg\.exe\"\ssave\shklm\\system\s.{0,1000} | greyware_tool_keyword | reg | saves a copy of the registry hive | T1003.002 | TA0009 | N/A | Dispossessor - Rancor - OilRig - Dragonfly - GALLIUM - Turla | Collection | N/A | 1 | 0 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56877 |
| 605 | *RegHiveBackup.exe* | .{0,1000}RegHiveBackup\.exe.{0,1000} | offensive_tool_keyword | RegHiveBackup | backup the Registry files on your system into the specified folder | T1012 - T1596 - T1003 | TA0006 - TA0009 | N/A | N/A | Collection | https://www.nirsoft.net/alpha/reghivebackup.zip | 1 | 1 | #registry | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56887 |
| 606 | *rundll32.exe C:\windows\System32\comsvcs.dll MiniDump (Get-Process lsass).id* | .{0,1000}rundll32\.exe\sC\:\\windows\\System32\\comsvcs\.dll\sMiniDump\s\(Get\-Process\slsass\)\.id.{0,1000} | offensive_tool_keyword | powershell | credential dumping activity | T1003.001 | TA0006 | N/A | N/A | Collection | https://www.trendmicro.com/en_us/research/22/g/analyzing-penetration-testing-tools-that-threat-actors-use-to-br.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57707 |
| 607 | *scan_with_trufflehog(* | .{0,1000}scan_with_trufflehog\(.{0,1000} | offensive_tool_keyword | webtrufflehog | Browser extension that leverages TruffleHog to scan web traffic in real-time for exposed secrets | T1552.001 - T1040 - T1036 - T1087 | TA0006 - TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/c3l3si4n/webtrufflehog | 1 | 0 | #content | N/A | 7 | 2 | 102 | 10 | 2024-12-29T23:26:35Z | 2024-12-28T19:53:09Z | 58097 |
| 608 | *scp -P *system_info.txt* | .{0,1000}scp\s\-P\s.{0,1000}system_info\.txt.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 58202 | |
| 609 | *shehzade/peeping-tom* | .{0,1000}shehzade\/peeping\-tom.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 1 | N/A | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 59278 |
| 610 | *skelsec/pysnaffler* | .{0,1000}skelsec\/pysnaffler.{0,1000} | offensive_tool_keyword | pysnaffler | This project is a Python version of the well-known Snaffler project. Not a full implementation of that project - only focusing on SMB share/dir/file enumeration and download and parse. | T1083 - T1087 - T1114 - T1518 | TA0007 - TA0009 - TA0010 | N/A | N/A | Collection | https://github.com/skelsec/pysnaffler | 1 | 1 | N/A | N/A | 10 | 1 | 91 | 5 | 2025-03-15T13:46:34Z | 2023-11-17T21:52:40Z | 59583 |
| 611 | *smukx@proton.me* | .{0,1000}smukx\@proton\.me.{0,1000} | offensive_tool_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 59760 | ||
| 612 | *trickster0/EDR_Detector* | .{0,1000}trickster0\/EDR_Detector.{0,1000} | offensive_tool_keyword | EDR_Detector | detect EDR agents on a machine | T1518.001 - T1063 | TA0007 - TA0009 | N/A | N/A | Collection | https://github.com/trickster0/EDR_Detector | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 14 | 2021-11-05T08:10:05Z | 2019-08-24T20:50:09Z | 61566 |
| 613 | *Trojan.Keylogger.Win32* | .{0,1000}Trojan\.Keylogger\.Win32.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 61577 | |
| 614 | *uknowsec/keylogger* | .{0,1000}uknowsec\/keylogger.{0,1000} | offensive_tool_keyword | keylogger | Keyboard recording | T1056.001 | TA0006 - TA0009 | N/A | N/A | Collection | https://github.com/uknowsec/keylogger | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 35 | 2021-05-19T08:33:58Z | 2020-11-10T07:15:50Z | 61810 |
| 615 | *VolumeShadowCopyTools.ps1* | .{0,1000}VolumeShadowCopyTools\.ps1.{0,1000} | offensive_tool_keyword | Powersploit | PowerSploit contains a PowerShell script which utilizes the volume shadow copy service to create a new volume that could be used for extraction of files | T1003 - T1103 - T1213 | TA0006 - TA0009 - TA0010 | N/A | Dispossessor - MAZE - Conti - PYSA - Avaddon - Black Basta - APT33 - Earth Lusca - APT41 - MuddyWater - FIN7 - menuPass - Leviathan - TA505 - Patchwork - FIN13 - WIZARD SPIDER - INDRIK SPIDER - PowerPool - APT32 - QUILTED TIGER - COZY BEAR - Turla | Collection | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62265 |
| 616 | *Volumiser.exe --image* | .{0,1000}Volumiser\.exe\s\-\-image.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 62267 |
| 617 | *Volumiser\DiscUtils.Ebs\EbsMappedStream* | .{0,1000}Volumiser\\DiscUtils\.Ebs\\EbsMappedStream.{0,1000} | offensive_tool_keyword | Volumiser | Volumiser is a command line tool and interactive console GUI for listing - browsing and extracting files from common virtual machine hard disk image formats. | T1560.001 - T1059 - T1114 - T1005 | TA0005 - TA0009 | N/A | N/A | Collection | https://github.com/CCob/Volumiser | 1 | 0 | N/A | N/A | 7 | 4 | 379 | 42 | 2025-04-22T15:47:53Z | 2022-11-08T21:38:56Z | 62268 |
| 618 | *vssadmin create shadow /for=C:* | .{0,1000}vssadmin\screate\sshadow\s\/for\=C\:.{0,1000} | greyware_tool_keyword | vssadmin | the command is used to create a new Volume Shadow Copy for a specific volume which can be utilized by an attacker to collect data from the local system | T1005 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 62281 |
| 619 | *vssadmin.exe Create Shadow /for=* | .{0,1000}vssadmin\.exe\screate\sshadow\s\/for\=.{0,1000} | greyware_tool_keyword | vssadmin | the command is used to create a new Volume Shadow Copy for a specific volume which can be utilized by an attacker to collect data from the local system | T1005 | TA0009 | N/A | N/A | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 62292 |
| 620 | *W32/KeyLogger.PMU!tr.spy* | .{0,1000}W32\/KeyLogger\.PMU!tr\.spy.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62334 | |
| 621 | *whoami.exe* /groups* | .{0,1000}whoami\.exe.{0,1000}\s\/groups.{0,1000} | greyware_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0007 | N/A | Black Basta | Collection | https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.yaml | 1 | 0 | N/A | greyware tool - risks of False positive ! | 8 | 10 | 10466 | 2904 | 2025-04-21T13:09:54Z | 2017-10-11T17:23:32Z | 62573 |
| 622 | *wifi_dos_own.py* | .{0,1000}wifi_dos_own\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 62583 |
| 623 | *wifi_dos3.py* | .{0,1000}wifi_dos3\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 62584 |
| 624 | *Win32/KidLogger* | .{0,1000}Win32\/KidLogger.{0,1000} | signature_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62636 |
| 625 | *Win32/Spy.KeyLogger.PMU* | .{0,1000}Win32\/Spy\.KeyLogger\.PMU.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62642 | |
| 626 | *Win32/Turla.BZ* | .{0,1000}Win32\/Turla\.BZ.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62644 | |
| 627 | *Win64/Turla.BQ* | .{0,1000}Win64\/Turla\.BQ.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62668 | |
| 628 | *Win64/Turla.BR* | .{0,1000}Win64\/Turla\.BR.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62669 | |
| 629 | *Win64/Turla.BS* | .{0,1000}Win64\/Turla\.BS.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62670 | |
| 630 | *Windows keyboard hook installed & log exfiltration timer started* | .{0,1000}Windows\skeyboard\shook\sinstalled\s\&\slog\sexfiltration\stimer\sstarted.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 62706 |
| 631 | *window-state@safejka.eu* | .{0,1000}window\-state\@safejka\.eu.{0,1000} | offensive_tool_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62772 | |
| 632 | *wmic.exe process call create *cmd /c * | .{0,1000}wmic\.exe\sprocess\scall\screate\s.{0,1000}cmd\s\/c\s.{0,1000} | greyware_tool_keyword | wmic | call cmd.exe with wmic | T1047 - T1059 | TA0002 - TA0009 | N/A | MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR | Collection | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 5 | 10 | N/A | N/A | N/A | N/A | 62956 |
| 633 | *workingKeyLog has been pushed to key log file!* | .{0,1000}workingKeyLog\shas\sbeen\spushed\sto\skey\slog\sfile!.{0,1000} | offensive_tool_keyword | peeping-tom | Remote keylogger for Windows written in C++ | T1056.001 - T1123 - T1129 - T1113 | TA0006 - TA0008 - TA0009 | N/A | Dispossessor | Collection | https://github.com/shehzade/peeping-tom | 1 | 0 | #content | keylogger | 10 | 1 | 3 | 0 | 2022-07-24T09:31:59Z | 2022-04-15T14:16:41Z | 63043 |
| 634 | *www.mediafire.com/file/* | .{0,1000}www\.mediafire\.com\/file\/.{0,1000} | greyware_tool_keyword | mediafire | downloading from mediafire | T1105 - T1114 - T1083 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 63155 |
| 635 | *www.mediafire.com/file/*.rar/file* | .{0,1000}www\.mediafire\.com\/file\/.{0,1000}\.rar\/file.{0,1000} | greyware_tool_keyword | mediafire | downloading from mediafire - rar archive | T1105 - T1083 - T1560 | TA0009 | N/A | Black Basta | Collection | N/A | 1 | 1 | #filehostingservice | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 63156 |
| 636 | *yeelight_discover.py* | .{0,1000}yeelight_discover\.py.{0,1000} | offensive_tool_keyword | red-python-scripts | random networking exploitation scirpts | T1190 - T1046 - T1065 | TA0001 - TA0007 | N/A | N/A | Collection | https://github.com/davidbombal/red-python-scripts | 1 | 0 | N/A | N/A | 8 | 10 | 2098 | 1599 | 2024-10-22T13:31:06Z | 2021-01-07T16:11:52Z | 63350 |
| 637 | *pentest-tools.com* | .{0,1000}pentest\-tools\.com.{0,1000} | offensive_tool_keyword | pentest-tools | cloud-based offensive security platform offering a wide range of automated penetration testing utilities | T1595.002 - T1046 - T1083 - T1059 - T1190 - T1203 | TA0007 - TA0001 - TA0002 | N/A | N/A | Collection | pentest-tools.com | 1 | 1 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 63729 |
| 638 | *swisskyrepo.github.io* | .{0,1000}swisskyrepo\.github\.io.{0,1000} | offensive_tool_keyword | pentest-tools | cloud-based offensive security platform offering a wide range of automated penetration testing utilities | T1595.002 - T1046 - T1083 - T1059 - T1190 - T1203 | TA0007 - TA0001 - TA0002 | N/A | N/A | Collection | N/A | 1 | 1 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 63730 |