Starred repositories
Tactical infrastructure mapping and attack visualization for offensive security operations
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
Erebus is an Initial Access wrapper for the Mythic Command & Control Server. It converts shellcode into payloads specifically used for phishing and IA operations.
A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and static signature removal.
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, certificate verification bypass, and DLL h…
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasio…
Use NtProtectVirtualMemory in Ekko timers without needing to use stack pivoting or other RSP shifting tricks
A centralized resource for previously documented WDAC bypass techniques
ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments
A collection of Azure AD/Entra tools for offensive and defensive security purposes
Deanonymize anyone based on their public commenting or posting history & pattern.
A WinForms wrapper for Nightmare Eclipse's YellowKey exploit, automating the creation of USB recovery media to access previously inaccessible files on Windows 11 systems.
Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows
BOF POC of the DSCourier project / invoking WinGet via COM
DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.
Object file loader implemented as a post-ex DLL for asynchronous BOF execution.
Async BOF to automatically extract or renew Kerberos TGTs on a target system.
A Cobalt Strike BOF implementation of the SilentHarvest registry dumping technique
FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading
A PoC UDRL for Cobalt Strike built with Crystal Palace that combines Raphael Mudge's page streaming technique with a modular call gate (Draugr)
Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames
crystal palace + draugr function hook definition generator
Project for generating and identifying deceptive LNK files.