Lists (32)
Sort Name ascending (A-Z)
APT
APT都在用
browser extension
C2相关,如SRDI,BOF
cloud
CTI
CTI tools
DFIR
DLL hijack
lsass
maldev academy
packer
phishing
purple team
reverse/debug
ROP
SOC
一些文档
内存加密
内网扫描
各类文本
堆栈欺骗
威胁情报
威胁模拟素材
学习可用
权限维持
检测
模板
混淆
研讨会
进程注入
Stars
☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
An AWS IAM Privilege Escalation Path Library
Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption
模拟cobalt strike beacon上线包. Simulation cobalt strike beacon connection packet.
JA4+ is a suite of network fingerprinting standards
An evolving repository of CloudTrail events with detailed descriptions, MITRE ATT&CK insights, real-world incidents, references and security implications
Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared library. Format inspired by @rasta-mouse's LibTP.
Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, o…
Helping defenders learn and validate npm supply-chain detections with safe atomic tests.
Tool to enumerate privileged Scheduled Tasks on Remote Systems
Synapse Rapid Power-Up for Validin
Usermode exploit to bypass any AC using a 0day shatter attack.
Repository for the DEATHCon 2025 Workshop "Operationzaling Purple Teaming in the Enterprise".
A rust proof of concept to demonstrate registry overwriting via RegRestoreKey using the Offline Registry Library
A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such as Zoom.
SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative featur…
Things i do because i saw it on twitter on a weekend
Live Feed of C2 servers, tools, and botnets