Highlights
- Pro
Stars
SCADAver: a Rust-powered, multi-protocol OT/ICS security framework for authorized labs featuring asset discovery, enumeration, controlled validation, simulators, and CLI, TUI, and web interfaces. D…
ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments
A centralized resource for previously documented WDAC bypass techniques
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code…
A command line process execution monitor for Windows.
Access All Networks: an offensive multitool against 802.1X
SOCKS5 proxy tool that uses Azure Storage services as a means of communication.
Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
Refusal handling skill for vulnerability research evals
rvrsh3ll / TextTransformer
Forked from secdev02/TextTransformerMore Than Meets the Eye
Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and per…
DCOM in memory and fileless lateral movement techniques through .Net deserilization
Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.
A modern alternative Web-UI for the Mythic Command and Control Server
This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s…
Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.
Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.
This cheatsheet maps common impacket workflows to their modern alternatives
A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free binary.
In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit
Tailscale-based Windows VNC persistence tool with Session 0 isolation bypass, embedding a full WireGuard peer and RFB server into a single drop-in binary.
abusing windows toast notifications for fun and user manipulation
A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike
Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by BeichenDream.