Stars
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel” presented at DEF CON 34 and BSidesLV 2026. Covers malware development, EDR Architecture, EDR evasio…
Find memory corruption vulnerabilities in stripped binaries — no source code required. Lifts ELF to LLVM IR, filters with SSA taint analysis, verifies with KLEE/IKOS/SeaHorn/SMACK.
Another FAFO project: Weaponizing MSI installers for fileless code execution
A font-based deception tool for red teaming, security research, and whatever else.
Multi-agent framework for evidence-driven CVE research, exploitation, and validation.
Hades is a fully-featured cross-platform Chrome Extension agent. Hades is designed for Mythic 3.0 and newer.
SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative featur…
opinionated workflow on LLM driven development.
Windows protocol library, including SMB and RPC implementations, among others.
Evasive shellcode loader for bypassing event-based injection detection (PoC)
Defender Signature Update Race Condition LPE
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we confi…
Reverse engineering focusing on x64 Windows.
Dominate the domain. Relay to royalty.
Some notes + exercises that I've done during my study for the Offensive Security Exploit Developer.
This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stage…
All efforts for the AWE course and preparation for the Offensive Security Exploitation Expert (OSEE) exam.
A bunch of resources to prepare for the OSEE certification, Offensive Security's hardest course.
DriversHunterWindowsCatalog is an app that searches the Microsoft Update Catalog for driver packages, downloads the CABs, extracts them, and collects WDM `.sys` files.
Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and comprehensive network discovery. Export results as BloodHound‑…
gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
AdaptixC2 is a highly modular advanced redteam toolkit