Purpleteam
Purpleteam scripts simulation & Detection - trigger events for SOC detections (by mthcht)
UltimateAppLockerByPassList
The goal of this repository is to document the most common techniques to bypass AppLocker. (by api0cradle)
Purpleteam | UltimateAppLockerByPassList | |
---|---|---|
1 | 4 | |
123 | 1,817 | |
- | - | |
7.8 | 2.1 | |
27 days ago | 8 months ago | |
PowerShell | PowerShell | |
- | - |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Purpleteam
Posts with mentions or reviews of Purpleteam.
We have used some of these posts to build our list of alternatives
and similar projects.
UltimateAppLockerByPassList
Posts with mentions or reviews of UltimateAppLockerByPassList.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-09-11.
-
AppLocker - Deny vs Allow and Except
Check out the Ultimate AppLocker Bypass list and add those https://github.com/api0cradle/UltimateAppLockerByPassList
-
FSRM saved our asses
Too bad it's trivial to bypass. My favorite bypass is through alternate data streams, which Applocker is unaware of.
-
What group policy rule should ever network have?
Remember to block these writable paths in under c:\Windows: https://github.com/api0cradle/UltimateAppLockerByPassList/blob/master/Generic-AppLockerbypasses.md
- Safe powershell
What are some alternatives?
When comparing Purpleteam and UltimateAppLockerByPassList you can also consider the following projects:
MAL-CL - MAL-CL (Malicious Command-Line)
HardeningKitty - HardeningKitty - Checks and hardens your Windows configuration
awesome-lists - Security lists for SOC detections
AaronLocker - Robust and practical application control for Windows
chainsaw - Rapidly Search and Hunt through Windows Forensic Artefacts
LOLBAS - Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)