Skip to content
View sagiol's full-sized avatar

Block or report sagiol

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic…

Python 111 14 Updated Aug 13, 2026
HTML 1 Updated Jun 29, 2026

Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins

C 120 21 Updated Jul 12, 2026

Proof of concept to show that Edge stores credentials in cleartext

C# 541 111 Updated Jun 10, 2026

Microsoft Graph API post-exploitation framework with a browser-based GUI.

HTML 51 6 Updated Apr 15, 2026

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

602 115 Updated Jun 3, 2025

DFSCoerce exe revisited version with custom authentication

C 43 9 Updated Jan 13, 2024

Crystal Palace RDLL loader for Adaptix C2 with Ekko sleep obfuscation, IAT hooking via PICO, and per-section permission restoration

C++ 160 20 Updated Jun 5, 2026

The Azure Execution Tool

PowerShell 159 13 Updated Feb 6, 2026

A tool to easily perform GitLab Device Code Phishing on red team engagements

Python 51 6 Updated Feb 9, 2026

🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with native AdaptixC2 integration. Drop it. Stream it. Watch it. Ki…

C 23 5 Updated Jul 28, 2026

A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.

C# 148 24 Updated Nov 21, 2021

Simulation and red team Phishing Framework

Go 242 38 Updated Aug 16, 2026

Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service loaders, set descriptions, and run them on demand.

Python 127 15 Updated Dec 7, 2025

SafeCrypt is an academic ransomware simulation suite developed for Red Team engagements. It demonstrates modern malware techniques including AES-256 stream encryption, asymmetric key exchange, and …

Go 37 6 Updated Oct 3, 2025

Windows protocol library, including SMB and RPC implementations, among others.

C# 825 85 Updated Aug 5, 2026

🔌Plug & Play🎮 Installer for 🐉Kali Linux offensive "Weapons" - Built for 'Offensive Security' teams.

Shell 7 Updated Jul 6, 2025

A set of programs for analyzing common vulnerabilities in COM

C++ 265 42 Updated Sep 8, 2024

Injecting DLL into LSASS at boot

C 158 36 Updated Apr 29, 2025

NTDLL unhooking via Parun's Fart technique to bypass EDR userland hooks

C++ 75 9 Updated Feb 15, 2023

Tool to perform lateral movement between AAD joined devices

Python 67 15 Updated Jun 8, 2022
Python 91 16 Updated Jul 28, 2022

Active Directory and Internal Pentest Cheatsheets

HTML 2,367 441 Updated Aug 16, 2026

365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.

PHP 584 111 Updated Mar 6, 2026

C# Lsass parser

C# 298 52 Updated Oct 13, 2021

Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.

Shell 212 21 Updated Mar 14, 2025

This script analyzes the DCSync output file from several tools (such as Mimikatz, Secretsdump and SharpKatz...)

Python 72 6 Updated Mar 17, 2025

A C++ proof of concept demonstrating the exploitation of Windows Protected Process Light (PPL) by leveraging COM-to-.NET redirection and reflection techniques for code injection. This PoC showcases…

C++ 336 48 Updated Mar 6, 2025

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end to end.

YARA 1,517 171 Updated May 5, 2026

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).

Rust 908 133 Updated Aug 18, 2026
Next