Stars
Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic…
Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins
Proof of concept to show that Edge stores credentials in cleartext
Microsoft Graph API post-exploitation framework with a browser-based GUI.
Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs
DFSCoerce exe revisited version with custom authentication
Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration
A tool to easily perform GitLab Device Code Phishing on red team engagements
🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with native AdaptixC2 integration. Drop it. Stream it. Watch it. Ki…
A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.
Simulation and red team Phishing Framework
Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service loaders, set descriptions, and run them on demand.
SafeCrypt is an academic ransomware simulation suite developed for Red Team engagements. It demonstrates modern malware techniques including AES-256 stream encryption, asymmetric key exchange, and …
Windows protocol library, including SMB and RPC implementations, among others.
🔌Plug & Play🎮 Installer for 🐉Kali Linux offensive "Weapons" - Built for 'Offensive Security' teams.
A set of programs for analyzing common vulnerabilities in COM
Injecting DLL into LSASS at boot
NTDLL unhooking via Parun's Fart technique to bypass EDR userland hooks
Tool to perform lateral movement between AAD joined devices
Active Directory and Internal Pentest Cheatsheets
365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.
This script analyzes the DCSync output file from several tools (such as Mimikatz, Secretsdump and SharpKatz...)
A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection. This PoC showcases…
A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).