Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A VBA implementation of the RunPE technique or how to bypass application whitelisting.
Writing custom backdoor payloads with C# - Defcon 27 Workshop
DEFCON 27 workshop - Modern Debugging with WinDbg Preview
SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by…
Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Coba…
The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.
Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors
Various Aggressor Scripts I've Created.
This repo contains some Amsi Bypass methods i found on different Blog Posts.
PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
The ultimate WinRM shell for hacking/pentesting
A TCP proxy over named pipes. Originally created for maintaining a meterpreter session over 445 for less network alarms.
Obfuscate specific windows apis with different apis
SharpSploit is a .NET post-exploitation library written in C#
.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters