-
Tier Zero Security
Stars
Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking across 19 file types, WinVerifyTrust FinalPolic…
A font-based deception tool for red teaming, security research, and whatever else.
A collection of libraries and a TUI to test fiber GPON deployments.
Silent;Call — Pre-authentication remote root on Cisco CUCM 15.x (CVSS 10.0)
POC tool for ResetNightmare (CVE-2026-27912)
BOF exploiting the Visual Studio Installer Elevation Service for SYSTEM LPE and persistence via AppDomainManager hijacking, with native ETW evasion. For Cobalt Strike & Adaptix.
An LLM extension for Ghidra to enable AI assistance in RE.
SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections.
PoC VS Code extension that silently exfiltrates GitHub OAuth tokens by spoofing a product-trusted extension identity.
Windows Kernel-Mode Shellcode Development Framework (WKMSDF)
Request a service ticket from a foreign DC using an inter-realm TGT, for cross-realm cases Impacket's getST.py mishandles
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
20 MB lightweight cross-platform database client for 70+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB, DuckDB, SQL Server, and Dameng. Built-in AI, MCP Server, CLI, desktop and Do…
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
BingusLdr is a DLL loader built with Crystal Palace that uses a CET compatible stack spoofing technique.
A Proof of Concept demonstrating CET-compliant callstack spoofing in Rust. It leverages Windows Thread Pool and Enum Callback trampolining (e.g., EnumSystemLocalesEx) to forge a pristine, hardware-…
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
Living Off the Land Credentials. Public credential defaults, locations, and exposure patterns for real products, SaaS/cloud services, appliances, and deployment packages.
BOF to manage Active Directory Integrated DNS (ADIDNS)