Starred repositories
Self-hosted web app that automates downloading, organizing, and scheduling YouTube channel content with support for Plex, Kodi, Emby and Jellyfin
Rust tool to detect cell site simulators on an orbic mobile hotspot
Hashtopolis - distributed password cracking with Hashcat
Use SE_BACKUP_NAME/SeBackupPrivilege to access objects you shouldn't have access to
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode
This repo contains some Amsi Bypass methods i found on different Blog Posts.
A community-driven collection of themes for customizing Spotify through Spicetify - https://github.com/spicetify/cli
Make BASH stealthy and hacker friendly with lots of bash functions
NixOS configuration for tunneling an inbound SSH connection over an outbound HTTPS connection
Sandman is a NTP based backdoor for hardened networks.
Reflective PE loader written in Rust. Loads and executes native and .NET PE files directly from memory.
This cheat sheet outlines common enumeration and attack methods for Windows Active Directory using PowerShell.
proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained p…
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
Abusing impersonation privileges through the "Printer Bug"
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
Windows Privilege Escalation from User to Domain Admin.
Proof of concept for injecting simple shellcode via ptrace into a running process.
The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.
Scripts I use to deploy Havoc on Linode and setup categorization and SSL
Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".