-
TrustTunnel Public
Forked from TrustTunnel/TrustTunnelModern, fast and obfuscated VPN protocol
Rust Apache License 2.0 UpdatedFeb 20, 2026 -
SPITkey Public
Forked from en4rab/SPITkeyDecrypt the bitlocker FVEK for a bitlocker encrypted drive.
Python GNU General Public License v3.0 UpdatedFeb 19, 2026 -
CVE-2026-20817 Public
Forked from oxfemale/CVE-2026-20817Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.
C++ GNU Affero General Public License v3.0 UpdatedFeb 18, 2026 -
TPM2-NV_Read-Secret-Extractor Public
Forked from CYLOQ/TPM2-NV_Read-Secret-ExtractorSaleae Logic 2 HLA plugin that extracts NV index data returned by TPM2_NV_Read from TPM2 SPI bus captures.
Python UpdatedFeb 18, 2026 -
Nidhogg Public
Forked from Idov31/NidhoggNidhogg is an all-in-one simple to use rootkit.
C++ GNU General Public License v3.0 UpdatedFeb 18, 2026 -
FrankensteinAPCInjection Public
Forked from S12cybersecurity/FrankensteinAPCInjectionNovel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueApcThreadEx2) for stealthy execution. Minimal permissions, no …
-
WebClientRelayUp Public
Forked from Hack0ura/WebClientRelayUpWebClientRelayUp - an universal no-fix local privilege escalation in domain-joined windows workstations in default configuration.
C# Apache License 2.0 UpdatedFeb 16, 2026 -
-
Simple-Crystal-Palace-RDLL-template-for-Adaptix Public
Forked from h41th/Simple-Crystal-Palace-RDLL-template-for-AdaptixC BSD 3-Clause "New" or "Revised" License UpdatedFeb 12, 2026 -
-
-
CobaltStrike-Linux-Beacon Public
Forked from EricEsquivel/CobaltStrike-Linux-BeaconProof of Concept (PoC) implant for creating custom Cobalt Strike Beacons
C UpdatedFeb 11, 2026 -
rustbof Public
Forked from joaoviictorti/rustbofA Rust template for writing Beacon Object Files (BOFs)
Rust Apache License 2.0 UpdatedFeb 11, 2026 -
-
PortForwarder Public
Forked from lsecqt/PortForwarderTCP Port Forwarding Utility on C
C UpdatedFeb 11, 2026 -
AutoPtT Public
Forked from ricardojoserf/AutoPtTAutomated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack, implemented in C++ and Python.
C++ UpdatedFeb 10, 2026 -
-
scfw Public
Forked from wbenny/scfwA cross-platform C++ framework for building Windows shellcode
C++ MIT License UpdatedFeb 9, 2026 -
agscript_middleware Public
Forked from NoahKirchner/agscript_middlewareRun CobaltStrike aggressorscript over TCP
UpdatedFeb 9, 2026 -
CVE-2025-61155 Public
Forked from pollotherunner/CVE-2025-61155Official public advisory for CVE-2025-61155
C++ UpdatedFeb 9, 2026 -
RecoverIt Public
Forked from TwoSevenOneT/RecoverItA tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy
C++ UpdatedFeb 8, 2026 -
malasada Public
Forked from sliverarmory/malasadaLinux Shared Library to Shellcode Loader
Assembly GNU General Public License v3.0 UpdatedFeb 7, 2026 -
DuplexSpyCS Public
Forked from iss4cf0ng/DuplexSpyCSA Remote Access Tool developed in C#, enabling complete control of a remote Windows machine, designed for legitimate remote administration and security testing of Windows systems.
C# MIT License UpdatedFeb 7, 2026 -
CustomDpapi Public
Calling the undocumented DPAPI RPC interface directly, no more calling public CryptUnprotectData!
-
Cobaltstrike_BOFLoader Public
Forked from CodeXTF2/Cobaltstrike_BOFLoaderopen source port/reimplementation of the Cobalt Strike BOF Loader as is
C UpdatedFeb 3, 2026 -
GhostKatz Public
Forked from RainbowDynamix/GhostKatzDump LSASS via physical memory read primitives in vulnerable kernel drivers
C MIT License UpdatedFeb 2, 2026 -
RelayKing-Depth Public
Forked from depthsecurity/RelayKing-DepthDominate the domain. Relay to royalty.
Python Other UpdatedJan 30, 2026 -
keycred Public
Forked from RedTeamPentesting/keycredGenerate and Manage KeyCredentialLinks
Go MIT License UpdatedJan 30, 2026 -
ColdWer Public
Forked from 0xsh3llf1r3/ColdWerCobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
C MIT License UpdatedJan 29, 2026 -
CVE-2025-5419 Public
Forked from bjrjk/CVE-2025-5419An uninitialized read vulnerability by incorrect Turboshaft Store-Store Elimination in V8.
JavaScript UpdatedJan 29, 2026