Stars
- All languages
- AGS Script
- ASP.NET
- AppleScript
- Assembly
- AutoHotkey
- AutoIt
- Awk
- Batchfile
- Bicep
- Boo
- C
- C#
- C++
- CSS
- Clojure
- CoffeeScript
- Crystal
- Cuda
- Cypher
- Dart
- Dockerfile
- EJS
- Elixir
- F#
- Fluent
- Go
- Groovy
- HCL
- HTML
- Handlebars
- Haskell
- JCL
- Java
- JavaScript
- Jinja
- Jsonnet
- Jupyter Notebook
- Just
- Kotlin
- Lua
- MDX
- Makefile
- Markdown
- Nim
- Nix
- Objective-C
- Objective-C++
- Open Policy Agent
- PHP
- Pascal
- Perl
- PowerShell
- Python
- REXX
- Raku
- Ruby
- Rust
- SCSS
- Scala
- Scheme
- Shell
- Smarty
- Starlark
- Svelte
- Swift
- Text
- TypeScript
- VBA
- VBScript
- Vala
- Vim Script
- Visual Basic
- Visual Basic .NET
- Vue
- XSLT
- YAML
- YARA
- Zeek
- Zig
Agent skill: make LLMs write docs in ASD-STE100 Simplified Technical
CnaEmulator is a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna)
Documentation and tools to access Windows Defender Application Control (WDAC) technology.
An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.
Kumo 蜘蛛 is a domain OSINT & security reconnaissance framework. Drop a domain, get everything back in real time across 27 parallel modules: DNS, open ports, leaked credentials, infostealer infection…
OneDrive as a covert C2 transport for Cobalt Strike
A Python CLI tool that converts Claude Code transcript JSONL files into readable HTML / Markdown format.
View Claude chat conversations in the browser, from exported JSON files
Advanced Windows authentication token extraction and decryption tool for red team operations and security research
M365AutoLink creates shortcuts in your Onedrive, silently, to all teams/sharepoint sites you have access
Ask the Web Account Manager (WAM) for Entra ID tokens
C# tool that verifies the status of WebClient services across multiple targets in the domain.
Open-source DOCX comparison tool to generate native Word tracked changes (redlines) in Python without MS Word dependencies
Recover NT hashes from NetNTLMv1 responses using local WebGPU computation and local/remote table lookup
Tiny Python tool that politely pokes SMB and asks: “Do you require signing?”
Powershell scripts for Winget with SCCM/Intune
A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
Crowdstrike Falcon 0day Privilege Escalation Vulnerability
The great impacket example scripts compiled for Windows
Advanced keyboard-walk generator with configureable basechars, keymap and routes
Tools I use on red team engagements and more
A group of Bofs made by me, with alot of help from the internet.
Cobalt Strike BOF to zip multiple files and directories on the target using ZIP64+DEFLATE, with compression levels 0–10. Directory trees are included with relative paths. Built-in failsafes close h…