Skip to content
View DrorDvash's full-sized avatar

Highlights

  • Pro

Block or report DrorDvash

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.

C 51 5 Updated Jun 17, 2026

A modern alternative Web-UI for the Mythic Command and Control Server

TypeScript 76 6 Updated Jun 7, 2026

This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library

304 28 Updated May 24, 2026

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

Python 2,007 419 Updated Jun 6, 2026

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Python 156 9 Updated Jun 8, 2026

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s…

Python 2,346 371 Updated May 8, 2026

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

Nim 402 45 Updated Jun 17, 2026

Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.

C 45 5 Updated Jun 18, 2026

This cheatsheet maps common impacket workflows to their modern alternatives

293 21 Updated May 30, 2026

Gopacket is a clean Go implementation of Impacket, a library intended for working with network protocols.

Go 677 56 Updated Jun 9, 2026

Claude Desktop for Linux

Shell 4,984 496 Updated Jun 19, 2026

In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit

Python 19 Updated Apr 14, 2026

Tailscale-based Windows VNC persistence tool with Session 0 isolation bypass, embedding a full WireGuard peer and RFB server into a single drop-in binary.

Go 297 35 Updated Apr 11, 2026

abusing windows toast notifications for fun and user manipulation

C 103 11 Updated Jun 2, 2026

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

C 231 29 Updated Apr 11, 2026

Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by BeichenDream.

C 264 33 Updated Apr 16, 2026

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

JavaScript 217,878 33,425 Updated Jun 19, 2026

The Fully Customizable Desktop Environment for Windows 10/11.

Rust 17,097 552 Updated Jun 19, 2026

Agent for AdaptixC2 with focus in evasion, capability and malleable.

C 214 51 Updated Apr 26, 2026

A curated list of Claude Skills.

9,548 1,242 Updated Jun 3, 2026

The SpecterOps project management and reporting engine

Python 1,842 248 Updated Jun 19, 2026

Agentic AI Infrastructure for magnifying HUMAN capabilities.

TypeScript 16,001 2,206 Updated May 20, 2026

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

HTML 1,308 164 Updated Jun 9, 2026

A tool leveraging Kerberos tickets to get Microsoft 365 access tokens using Seamless SSO

Python 244 16 Updated Aug 25, 2024

Chrome browser extension-based Command & Control

HTML 259 33 Updated Mar 18, 2026

FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.

Python 22 3 Updated May 5, 2025

Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.

C 238 47 Updated May 4, 2026

KslDump — Why bring your own knife when Defender already left one in the kitchen?

Python 350 42 Updated Apr 13, 2026

BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.

C 83 6 Updated Apr 11, 2026

Extract Windows credentials directly from VM memory snapshots and virtual disks

Rust 1,370 150 Updated Jun 7, 2026
Next