Lists (21)
Sort Name ascending (A-Z)
Active Directory Pwnage
AI / LLM
Cloud Pwnage
Cracking
Defending / Blue Team
Evasion
Hacking Labs
Honeypots
Infrastructure Pwnage
Linux Pwnage
Mobile Pwnage
OSINT / Enumeration
Phishing & Awareness
Privilege Escalation / Looting
Red Teaming
Reporting
SAP Hacking
SAST / DAST
Selfhosting / DevOPS
Web Pwnage
Wireless Hacking
Stars
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Small and highly portable detection tests based on MITRE's ATT&CK.
Dopamine is a semi-untethered jailbreak for iOS 15 to 26(.0.1)
Jailbreak for A8 through A11, T2 devices, on iOS/iPadOS/tvOS 15.0, bridgeOS 5.0 and higher.
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 9…
PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
Collection of UAC Bypass Techniques Weaponized as BOFs
Crowdstrike Falcon 0day Privilege Escalation Vulnerability
MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.
LPE exploit for CVE-2023-21768
Utility to decrypt App Store apps on jailbroken iOS 11.x
Local privilege escalation via PetitPotam (Abusing impersonate privileges).
OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar
Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework
A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without touching LSASS process memory.
Slides & Code snippets for a workshop held @ x33fcon 2024
Silentbridge is a toolkit for bypassing 802.1x-2010 and 802.1x-2004.
Two tools written in C that block network traffic for blacklisted EDR processes, using either Windows Defender Firewall (WDF) or Windows Filtering Platform (WFP).
PoC demonstrating a multi process injection chain aimed at remotely executing shellcode
Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.
Lab research on Windows loader internals, PE loading, stack artifacts, and execution tradeoffs.