Stars
Neo4LDAP is a query and visualization tool focused on Active Directory environments. It combines LDAP syntax with graph-based data analysis in Neo4j, offering an alternative approach to tools like …
Reflective x64 PE/DLL Loader implemented using Dynamic Indirect Syscalls
Combining Sealighter with unpatched exploits to run the Threat-Intelligence ETW Provider
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
A modern 32/64-bit position independent implant template
This project aims to compare and evaluate the telemetry of various EDR products.
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
Kraken, a modular multi-language webshell coded by @secu_x11
A light-weight first-stage C2 implant written in Nim (and Rust).
A collaborative, multi-platform, red teaming framework
A tool that shows detailed information about named pipes in Windows
Idapython script to carve binary for internal RPC structures
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass…
A string obfuscator for .NET apps, built to evade static string analysis.
Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams
Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth.
Create fake certs for binaries using windows binaries and the power of bat files
Create polyglot files, which are valid PDF and ZIP simultaneously. See POC||GTFO 07. (forked from git.hackade.org)
Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types
Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
Collection of various malicious functionality to aid in malware development
.NET, PE, & Raw Shellcode Packer/Loader Written in Nim