Stars
Custom Amsi Bypass by patching AmsiOpenSession function in amsi.dll
OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup
Situational Awareness commands implemented using Beacon Object Files
Situational Awareness commands implemented using Beacon Object Files
Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.
ArtWeb: Lightweight Cross-Platform HTTP(S) Server written in C
A new AMSI Bypass technique using .NET ALI Call Hooking.
Monitor linux processes without root permissions
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
Evil SQL Client (ESC) is an interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration features. While ESC can be a handy SQL Client for daily tasks, it w…
Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
Extracting Clear Text Passwords from mstsc.exe using API Hooking.
Tool to bypass LSA Protection (aka Protected Process Light)
Abusing impersonation privileges through the "Printer Bug"
PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
Modified Spool Sample for SEImpersonate Privilege Escalation.
A collection of useful tools and scripts were developed and gathered throughout the Offensive Security's PEN-300 (OSEP) course.
DebugAmsi is another way to bypass AMSI through the Windows process debugger mechanism.
A tool to create a JScript file which loads a .NET v2 assembly from memory.
A workshop about Malware Development
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
Use SE_BACKUP_NAME/SeBackupPrivilege to access objects you shouldn't have access to
A Python based ingestor for BloodHound
World's fastest and most advanced password recovery utility
Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).
Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
Kernel mode WinDbg extension and PoCs for token privilege investigation.