aboutsummaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorFilesLines
2013-11-13Normalized all scripts to ASCII encodingmattifestation58-91/+91
2013-11-07Get-ILDisassembly now accepts ConstructorInfo objectsmattifestation1-3/+4
2013-11-07Get-ILDisassembly now displays metadata tokens.mattifestation2-1/+9
* Having metadata tokens displayed in output helps with reverse engineering because you can pass metadata tokens to System.Reflection.Module.ResolveMember and then easily interact with the member in question. * I also fixed a bug when displaying integer constants. I wasn't doing an endian swap.
2013-11-04Merge pull request #19 from clymb3r/masterMatt Graeber1-2/+2
Updated Invoke-TokenManipulation help
2013-11-04Updated Invoke-TokenManipulation helpclymb3r1-2/+2
2013-11-04Added Invoke-TokenManipulation to README.mdmattifestation1-0/+4
2013-11-04Merge pull request #18 from clymb3r/masterMatt Graeber2-1/+1774
Adding Invoke-TokenManipulation
2013-11-03Adding Invoke-TokenManipulationclymb3r2-1/+1774
2013-11-03Fix for hostfiles option in powershell 2webstersprodigy1-2/+2
2013-11-03Updated usage tipmattifestation1-1/+4
2013-11-03Added a usage tipmattifestation1-0/+2
Added a one-liner for PSv3 that will remove the annoying warnings that are displayed when importing scripts downloaded from the Internet.
2013-11-03Slight clarification to license statementmattifestation1-1/+1
2013-11-03Modified license verbiagemattifestation1-1/+1
2013-11-03Added exfil script synopses to README.mdmattifestation1-0/+8
Descriptions for Invoke-NinjaCopy and Invoke-Mimikatz were added to the readme.
2013-11-03Fixed minor logic bug in C type undecorated symbolsmattifestation1-1/+8
2013-11-03Added Get-LibSymbolsmattifestation4-2/+313
Get-LibSymbols parses Microsoft .lib files and displays decorated and undecorated symbols.
2013-10-23Merge pull request #17 from webstersprodigy/portscan-hostlist-fixMatt Graeber1-2/+2
Fix for hostfiles option in powershell 2
2013-10-22Fix for hostfiles option in powershell 2webstersprodigy1-2/+2
2013-10-05Updated usage tipmattifestation1-1/+4
2013-10-05Added a usage tipmattifestation1-0/+2
Added a one-liner for PSv3 that will remove the annoying warnings that are displayed when importing scripts downloaded from the Internet.
2013-10-05Slight clarification to license statementmattifestation1-1/+1
2013-10-05Merge pull request #16 from clymb3r/masterMatt Graeber3-8/+8
Switching to ANSI from UTF8 encoding
2013-10-01Switching to ANSI from UTF8 encodingclymb3r3-8/+8
Scripts now work in 2008r2. I thought I tested before uploading but something broke somehow... Now the scripts work in 2008r2 and win8+
2013-10-01Modified license verbiagemattifestation1-1/+1
2013-10-01Added exfil script synopses to README.mdmattifestation1-0/+8
Descriptions for Invoke-NinjaCopy and Invoke-Mimikatz were added to the readme.
2013-10-01Merge pull request #15 from clymb3r/masterMatt Graeber319-1/+29696
Adding GitIgnore, adding Invoke-NinjaCopy and Invoke-Mimikatz
2013-10-01Adding Invoke-Mimikatz and Invoke-Ninjacopyclymb3r318-1/+29481
2013-10-01Adding gitignore fileclymb3r1-0/+215
Don't want gigantic ipch files from visual studio (among other useless files) to be uploaded.
2013-10-01Merge pull request #14 from clymb3r/masterMatt Graeber1-2593/+2575
Fixes for Windows 8.1/.NET 4.5
2013-09-30Fixes for Windows 8.1/.NET 4.5clymb3r1-2593/+2575
.NET 4.5 introduced breaking changes in the way Marshalling works. Added a fix so ReflectivePEInjection works with Windows 8.1/.NET4.5.
2013-09-30Fixed minor logic bug in C type undecorated symbolsmattifestation1-1/+8
2013-09-29Added Get-LibSymbolsmattifestation4-2/+313
Get-LibSymbols parses Microsoft .lib files and displays decorated and undecorated symbols.
2013-09-04Merge pull request #13 from clymb3r/masterMatt Graeber1-0/+9
Call to DllMain when unloading reflective DLL
2013-09-03Call to DllMain when unloading reflective DLLclymb3r1-0/+9
Prior to this fix, DllMain with the ProessDetach flag was not called when unloading the reflectively loaded DLL. This was causing very weird crashes in the Invoke-NinjaCopy script which is built on this script. This should fix the crash.
2013-08-29Added ProcessModuleTrace cmdletsmattifestation4-2/+153
Added *-ProcessModuleTrace cmdlets to trace details when modules are loaded into a process. These can be useful for malware analysis.
2013-08-17Explicitly casting types as [Type]v2.2Matt Graeber2-6/+6
The latest version of .NET added generics to many of the InteropService methods. Therefore, all of my uses of types need to be explicitly cast with [Type].
2013-08-17Added ps1xml file for Get-ILDisassemblyMatt Graeber3-3/+46
Output from Get-ILDisassembly is slightly cleaner.
2013-08-17Removing Get-PEArchitectureMatt Graeber3-100/+1
This functionality is present and maintained in Get-PEHeader.
2013-08-17Get-Keystrokes now accepts relative pathsMatt Graeber1-1/+3
2013-08-17Out-Minidump now provides descriptive outputMatt Graeber1-2/+2
Out-Minidump now outputs a FileInfo object (i.e. the same output as Get-ChildItem) upon successfully creating a dump file.
2013-08-17Added additional error handling to Get-GPPPasswordMatt Graeber1-3/+10
2013-08-17Merge pull request #11 from hajdbo/patch-1Matt Graeber1-2/+2
added ErrorAction SilentlyContinue to Get-ChildItem
2013-08-16Compiler parameters were not applied to Add-TypeMatt Graeber1-4/+2
The compiler parameters were not being applied to Add-Type in Get-PEHeader. Derp. This led to unexpected errors when Visual Studio environment variables were defined.
2013-08-12added ErrorAction SilentlyContinue to Get-ChildItemhajdbo1-2/+2
Sometimes you will have a denied access to a directory. "ErrorAction SilentlyContinue" will continue searching recursively in \SYSVOL even when it encounters a directory where access is denied.
2013-07-28Get-PEHeader can now return raw section dataMatt Graeber1-7/+45
2013-07-28Latest version of .NET Framework broke Get-PEHeaderMatt Graeber1-15/+15
To fix this, I needed to explicitly cast types in the SizeOf and PtrToStructure methods.
2013-07-11Latest version of .NET Framework broke Get-PEBMatt Graeber1-12/+12
To fix this, I needed to explicitly cast types in the SizeOf and PtrToStructure methods.
2013-07-09Added Get-ObjDumpMatt Graeber4-2/+1007
Get-ObjDump parses and return information about one or more Windows object files. It is similar to dumpbin but it returns objects!
2013-07-06Merge pull request #10 from mattifestation/webstersprodigy-PortscanMatt Graeber3-2/+1094
Webstersprodigy portscan
2013-07-06Added Invoke-Portscan to READMEMatt Graeber1-0/+4