Stars
Cobalt Strike Beacon Object File to enable the webdav client service on x64 windows hosts
Extract hashes from VBK files -- cause it's fun...
POC tool for ResetNightmare (CVE-2026-27912)
Passkeys/FIDO2/WebAuthn .NET Library for Windows Desktop and CLI Applications
Python collector for adding SCCM attack paths to BloodHound with OpenGraph
Encrypted shellcode Injection to avoid Kernel triggered memory scans
A Python library for extracting structured information from unstructured text using LLMs with precise source grounding and interactive visualization.
P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and staging location for shellcode injection into remote …
PoC for exploiting CVE-2026-26128.
Abusing the win32k.sys kernel callback mechanism for arbitrary code execution
Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advanced techniques to dump memory, allowing to access sensitive da…
Beacon Object File to Enable Chrome DevTools Protocol (CDP)
Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from silent in-process BOF to full PowerShell/WMI.
A compiled language for Windows position-independent x86-64 shellcode and Beacon Object Files.
Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.
Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.
Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution experiments
A credential extraction .NET assembly for Veeam Backup & Replication and Veeam One
PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping
DCOM in memory and fileless lateral movement techniques through .Net deserilization
RoguePlanet Windows Defender Vulnerability