Skip to content
View thecybermafia's full-sized avatar

Block or report thecybermafia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
Python 15 1 Updated Nov 10, 2025

Prevent in-process process termination by patching exit APIs

C++ 51 4 Updated Nov 9, 2025

Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence

Python 308 57 Updated Nov 7, 2025

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using the MS-WCCE protocol over DCOM and It bypasses …

C# 137 17 Updated Nov 2, 2025

NoMoreStealers is a Windows file system minifilter driver that protects sensitive user data from untrusted processes.

JavaScript 57 11 Updated Nov 7, 2025
Python 37 1 Updated Jan 7, 2025

A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks.

Python 179 34 Updated Apr 23, 2021

Fast covert timing channel communication for inter-process and inter-processor communication on Windows systems.

C++ 60 5 Updated Oct 30, 2025

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.

Nim 203 22 Updated Nov 12, 2025

This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.

JavaScript 64 18 Updated Jan 8, 2025

Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database

Python 201 30 Updated Nov 3, 2025

GeoIntel using Google's Gemini API to uncover the location where photos were taken through AI-powered geo-location analysis.

HTML 759 87 Updated Nov 12, 2025

Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopeful…

PowerShell 126 12 Updated Oct 30, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 63 10 Updated Oct 22, 2025

free, open-source file scanner

TypeScript 336 15 Updated Nov 10, 2025

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using Windows Filtering Platform (WFP). This version fo…

C 240 30 Updated Nov 3, 2025

EDR-Redir : a tool used to redirect the EDR's folder to another location.

C++ 152 24 Updated Nov 6, 2025

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 416 33 Updated Oct 27, 2025

The DCERPC only printerbug.py version

Python 151 21 Updated Oct 30, 2025

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

PowerShell 41 2 Updated Oct 28, 2025

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 184 20 Updated Oct 30, 2025

WSUS Unauthenticated RCE

Python 153 21 Updated Oct 28, 2025

Exhaustive search and flexible filtering of Active Directory ACEs.

Python 62 8 Updated Nov 10, 2025

Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)

Python 112 8 Updated Oct 23, 2025

A Windows executable 'loader' (in-memory patcher) for x86 and x64 targets, designed for controlled in-memory patching of executables (PE images).

C++ 22 4 Updated Oct 30, 2025

GUI for apktool, signapk, zipalign and baksmali utilities.

C# 1,103 122 Updated Aug 2, 2025

Blocking Windows EDR agents by registering an own IPC-object in the Object Manager’s namespace (CVE-2023-3280, CVE-2024-5909, CVE-2024-20671)

C++ 33 3 Updated Feb 27, 2025

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security research and penetration testing! 🎫

C# 104 12 Updated Oct 21, 2025

Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does

Python 89 10 Updated Jul 3, 2025
Next