Skip to content
View d3adzo's full-sized avatar
💻
💻
  • nullptr

Organizations

@RITRedteam @ritsec

Block or report d3adzo

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Decentralized C2 framework built on libp2p

Go 446 65 Updated Jun 16, 2026

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Go 1,733 281 Updated Aug 13, 2026

ANIMO Azure Network Intel & Mission Ops a C2 based on Azure/Entra assessments

C++ 87 13 Updated Aug 7, 2026

Cobalt Strike BOF that extracts selected Windows registry hives directly from a raw NTFS volume by parsing NTFS metadata and reading file data straight from disk.

C 93 8 Updated Jun 17, 2026
C 4,978 785 Updated May 10, 2026

Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry

C# 479 46 Updated Aug 2, 2024

Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy

C 5,728 343 Updated Jul 31, 2026

Collect infrastructure and permissions data from vCenter and export it as a BloodHound‑compatible graph using Custom Nodes/Edges

Python 183 11 Updated Aug 13, 2025

A Python utility to dump Kubernetes resources and store them in BloodHound's OpenGraph

Python 9 1 Updated Sep 30, 2025

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft, and cloud IAM takeover.

Go 225 22 Updated Jul 1, 2026

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution…

Python 102 22 Updated Apr 29, 2026

🧠 The ultimate resource for finding Beacon Object Files (BOFs).

Python 151 23 Updated Aug 10, 2026

Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by BeichenDream.

C 277 35 Updated Apr 16, 2026

Evade EDR's the simple way, by not touching any of the API's they hook.

PHP 192 17 Updated Jun 27, 2026

BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing — no VSS, no Registry APIs, no PowerShell

C 134 8 Updated Apr 6, 2026

Rotating socks proxy

Rust 4 Updated Apr 4, 2026

A first-come first-served single-fire HTTP server. Easily transfer files to and from your terminal and any browser.

Go 341 10 Updated Jun 11, 2026

Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable API calls.

C 146 16 Updated Apr 22, 2026

InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditiona…

C 767 141 Updated Jul 22, 2023

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

Python 163 10 Updated Jul 15, 2026

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

C 135 9 Updated Mar 27, 2026

🔥 Rotating proxy network on Cloudflare Workers. Deploy, rotate, fire.

TypeScript 51 4 Updated Apr 13, 2026

Dominate the domain. Relay to royalty.

Python 342 30 Updated Mar 31, 2026

A .NET Runtime for Cobalt Strike's Beacon Object Files

C 786 112 Updated Sep 4, 2024

Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domain joined machies

C# 312 31 Updated Mar 28, 2026

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Python 188 23 Updated Aug 16, 2025

Creative and unusual things that can be done with the Windows API.

C# 2,545 146 Updated Aug 22, 2022
C 194 12 Updated Oct 21, 2025

In-depth ldap enumeration utility

Python 601 67 Updated Jun 24, 2026

Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return address spoofing

C 80 6 Updated Mar 22, 2026
Next