Lists (1)
Sort Name ascending (A-Z)
Starred repositories
Ongoing collection of shellcode samples to be added to. Password: shellcode
This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution for Windows jump-oriented programming. JOP ROCK…
SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative featur…
Manual mapper that uses PTE manipulation, Virtual Address Descriptor (VAD) manipulation, and forceful memory allocation to hide executable pages. (VAD hide / NX bit swapping)
An script to perform kerberos bruteforcing by using impacket
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Exploits written by the Rhino Security Labs team
A collection of scripts for assessing Microsoft Azure security
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
⚡A CLI tool for code structural search, lint and rewriting. Written in Rust
"Bypassing" HVCI via donor PFN swaps to modify read-only code pages. Call chained kernel functions (kCET and SLAT support), and more.
Discover hidden debugging parameters and uncover web application secrets
Kaitai Struct: declarative language to generate binary data parsers in C++ / C# / Go / Java / JavaScript / Lua / Nim / Perl / PHP / Python / Ruby / Rust
This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)
PowerSploit - A PowerShell Post-Exploitation Framework
Impacket is a collection of Python classes for working with network protocols.
.NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins.
A little tool to play with Windows security
Passive hostname, domain and IP lookup tool for non-robots
Code signing and transparency for containers and binaries
Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.