Lists (19)
Sort Name ascending (A-Z)
Stars
Post-exploitation and evasion research toolkit for Linux.
WebStrike 是一套以 Chromium 系浏览器扩展(Manifest V3) 为受控端点的指挥与控制(C2)套件。与传统以进程/驱动为主的 C2 相比,其工作重心落在 浏览器安全域:在合规授权与攻防演练场景下,可显著降低与终端 EDR 在 进程注入、驱动、内核回调 等层面的直接对抗成本,同时将能力锚定在用户 真实访问的 Web 会话 上。
MatouWebshell 是一款基于 Vue 3 和 Python 开发的开源 Webshell 管理与利用平台。支持高度自定义的流量伪装、内网穿透及内存马注入等功能。项目具有极高的扩展性,非常欢迎安全研究人员基于此开源架构进行二次开发(如自定义修改 Payload、新增混淆规则等)。
NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support
A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and indirect NTAPIs for core operations.
BOF to manage Active Directory Integrated DNS (ADIDNS)
a minimal, position-independent C shellcode framework for Windows x64. compiles entirely on Linux
Local privilege escalation via PetitPotam (Abusing impersonate privileges).
Another Windows Local Privilege Escalation from Service Account to System
Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019
DCOM in memory and fileless lateral movement techniques through .Net deserilization
Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
BOF and research notes from hunting execution paths, covering Shell.HWEventHandlerShellExecute COM execution through the AutoPlay IHWEventHandler flow + ssh-shellhost.exe direct PTY command executi…
A Beacon Object File (BOF) for Havoc/CS to Bypass PPL and Dump Lsass
Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-si…
PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping
Dump LSASS via physical memory read primitives in vulnerable kernel drivers
first public in-process reflective PE loader for .NET NativeAOT binaries. maps a NativeAOT executable into the current process and executes it, bypassing the standard Windows loader.
Evasive loader for .NET Framework assemblies