Stars
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
Nimbo-C2 is yet another (simple and lightweight) C2 framework
You didn't think I'd go and leave the blue team out, right?
A tool for pointesters to find candies in SharePoint
A web front-end for password cracking and analytics
A quick example of the Hells Gate technique in Nim
A curated list of awesome Nim frameworks, libraries, software and resources.
APT & CyberCriminal Campaign Collection
Collection of Windows Hacking Binaries
The idea is to collect all the C# projects that are Sharp{Word} that can be used in Cobalt Strike as execute assembly command.
Obfuscate ECMA CIL (.NET IL) assemblies to evade Windows Defender AMSI
C++ function that will automagically unhook a specified Windows API
A post exploitation framework designed to operate covertly on heavily monitored environments
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
Windows 10 Privilege Escalation (magnifier.exe) via Dll Search Order Hijacking
Collection of social engineering payloads
Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth.
C# Data Collector for the BloodHound Project, Version 3
A post exploitation tool based on a web application, focusing on bypassing endpoint protection and application whitelisting
Flamingo captures credentials sprayed across the network by various IT and security products.
Simple (relatively) things allowing you to dig a bit deeper than usual.
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)
A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
Extract credentials from lsass remotely