Stars
This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stage…
Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.
C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.
A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure.
Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the ServerLevelPluginDll edge by using MS-DNSP.
My portfolio website on azure infrastructure built with Terraform
Interactive, persistent shell for HTTP requests. Built with Rust for ultimate speed and simplicity.
Community-driven baseline to accelerate Intune adoption and learning.
win-proxychains is a proxychains clone for 64 bit Windows applications, with partial feature parity.
Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and Flare.
Binaries for the book Practical Malware Analysis
Free educational content on reverse engineering and malware analysis from the FLARE team
BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.
A collaborative, multi-platform, red teaming framework
Self-hosted purple-team assessment and reporting tool.
Creating a repository with all public Beacon Object Files (BoFs)
Indexes Sharepoint 365 sites and documents, outputting text to the console and JSON lines to a file, all only using stolen browser cookies. Also includes support for downloading files en mass. Genu…
Various public documents, whitepapers and articles about APT campaigns
Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles
Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (pa…