Stars
CAPSlock is an offline Conditional Access (CA) analysis tool built on top of a roadrecon database. It helps defenders, auditors, and red teams understand how Conditional Access policies actually be…
Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
This is a PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion
This is a VxLAN PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion
This is a GRE PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion
This is a PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion
Encrypted shellcode Injection to avoid Kernel triggered memory scans
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens from Chrome, Edge, Brave & Avast - fileless, user-…
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful pyth…
This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the …
Python utility that generates "imageless" QR codes in various formats
So, you think you have MFA? AAD/ROPC/MFA bypass testing tool
A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.
A collection of Azure AD/Entra tools for offensive and defensive security purposes
Research into Undocumented Behavior of Azure AD Refresh Tokens
xforcered / SoaPy
Forked from logangoins/SOAPySoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.
COM ViewLogger — new malware keylogging technique
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
AV/EDR Lab environment setup references to help in Malware development
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
A modern 32/64-bit position independent implant template
BOF for Kerberos abuse (an implementation of some important features of the Rubeus).
DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.
Win32 and Kernel abusing techniques for pentesters