{"repo":"MHaggis/NEBULA","free":true,"listed":false,"github":"https://github.com/MHaggis/NEBULA","clone":"git clone https://github.com/MHaggis/NEBULA.git","description":"Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques","language":"PowerShell","stars":131,"topics":["atomic-red-team","lolbas","powershell","red-team","windows","wmi","tui"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"NEBULA 🌌 Nefarious Execution & Behavioral Unit for LOLBAS Attacks An interactive PowerShell TUI for testing and exploring Windows execution techniques, COM objects, WMI methods, and LOLBAS (Living Off The Land Binaries and Scripts) techniques. Overview NEBULA is an atomic testing framework designed for security researchers, red teamers, and blue teamers to understand and test various Windows execution and persistence techniques in a controlled environment. Features 🎯 WMI Execution Techniques 💻 COM Object Techniques 🔒 Persistence Techniques 🛠️ LOLBAS Execution Methods 🔍 Advanced WMI Exploration NEBULA COM Menu Usage Navigation NEBULA uses a clean, menu-driven interface: - Number keys (1-7) : Select menu options - B : Back to previous menu - Q : Quit application Test Results Tracking All executed tests are logged with: - Timestamp - Test name - Technique used - Status (SUCCESS/FAILED/ERROR/DRY-RUN) - Details and output View results anytime via the \"View Test Results\" menu option. Requirements - Windows 10/11 or Windows Server 2016+ - PowerShell 5.1 or later - Administrator privileges (for some techniques) Example Payloads NEBULA includes example payloads in the examples/ folder for testing LOLBAS techniques. These payloads are sourced from Atomic Red Team. Available Test Payloads - regsvr32 squiblydoo.sct - RegSvr32 Squiblydoo technique (T1218.010) - mshta calc.hta - MSHTA remote HTA execution (T1218.005) - rundll32 calc.sct - Rundll32 JavaScript protocol (T1218.011) - ru","default_branch":null,"files":null,"tree":[],"storefront":"/r/MHaggis","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/MHaggis/NEBULA/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}