Outflank B.V.
- Amsterdam, Netherlands, EU
- http://www.outflank.nl
- info@outflank.nl
Repositories
-
RedELK
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
-
EvilClippy
A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
-
InlineWhispers
Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF)
-
FindObjects-BOF
A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.
-
Dumpert
LSASS memory dumper using direct system calls and API unhooking.
-
WdToggle
A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.
-
Ps-Tools
Ps-Tools, an advanced process monitoring toolkit for offensive operations
-
RedFile
Serving files with conditions, serverside keying and more.
-
Presentations
Presentation material presented by Outflank team members at public events.
-
TamperETW
PoC to demonstrate how CLR ETW events can be tampered.
-
Spray-AD
A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.
-
Scripts
Small scripts that make life better
-
Zipper
Zipper, a CobaltStrike file and folder compression utility.
-
Net-GPPPassword
.NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.
-
SharpHide
Tool to create hidden registry keys.
-
Recon-AD
Recon-AD, an AD recon tool based on ADSI and reflective DLL’s
-
Invoke-Templator
A PowerShell script to parse the docx/docm file format and update the template location.
-
Excel4-DCOM
PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)
-
Invoke-ADLabDeployer
Automated deployment of Windows and Active Directory test lab networks. Useful for red and blue teams.
-
PasswordDump2ELK
Clean public password dump files and store in ELK
-
external_c2
POC for Cobalt Strike external C2
-
Exploits
Exploits developped by Outflank B.V. team members
-
NetshHelperBeacon
Example DLL to load from Windows NetShell