-
ricardojoserf.github.io Public
My personal blog. Website: https://ricardojoserf.github.io/
-
spotify-playlist-downloader Public
Downloading Spotify Playlists
-
SAMDump Public
Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation
-
amazon-mwaa-RCE Public
RCE in Amazon Managed Workflows for Apache Airflow (MWAA) service
-
DoubleTeam Public
Listener that spawns a new tmux window for each incoming reverse shell + Supports listening on many ports
-
MemorySnitcher Public
Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or LoadLibrary in the IAT)
-
instagram-user-id Public
Get the user ID of any user in instagram
-
ricardojoserf.herokuapp.com Public
My personal blog
-
emqx-RCE Public
EMQX Dashboard Malicious Plugin leading to RCE
-
TrickDump Public
Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!
-
NativeDump Public
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
-
network-providers Public
Tests with Network Providers DLLs, adding some extra functionality to NPPSpy2 by @gtworek
-
dns-exfiltration Public
Notes and custom scripts for DNS exfiltration
-
NativeNtdllRemap Public
Remap ntdll.dll using only NTAPI functions with a suspended process
-
-
NativeBypassCredGuard Public
Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
-
NativeTokenImpersonate Public
Impersonate Tokens using only NTAPI functions
-
github-star-counter Public
Count the exact number of stars for any Github user
-
SharpNado Public
Repository to gather the .NET malware I will be developing
-
p-invoke.net Public
P/Invoke definitions from the most-of-the-time offline offline pinvoke.net. Website: https://ricardojoserf.gitbook.io/pinvoke
-
writeups Public
Vulnhub and HTB writeups
-
lsass-dumper-csharp Public
Custom lsass.exe dump using C#: XOR-encoding, Dynamic function resolution, using NTAPIs...
-
FakeRebootAlert Public
Simple Windows Forms App to deceive users into rebooting the system upon login. Useful when you have updated a registry key such as PPL and need a safe reboot
-
BOF_Files Public
Repository to gather the BOF files I will be developing
-
goNtdllOverwrite Public
Overwrite ntdll.dll's ".text" section to bypass API hooking. Getting the clean dll from disk, Knowndlls folder or a debugged process
-
pyNtdllOverwrite Public
Overwrite ntdll.dll's ".text" section to bypass API hooking. Getting the clean dll from disk, Knowndlls folder or a debugged process
-
SharpNtdllOverwrite Public
Overwrite ntdll.dll's ".text" section to bypass API hooking. Getting the clean dll from disk, Knowndlls folder, a debugged process or a URL
-
SharpProcessDump Public
Dump memory regions of a process using NtQueryVirtualMemory and NtReadVirtualMemory
-
SharpCovertTube Public
Youtube as C2 channel - Control Windows systems uploading QR videos to Youtube
-
OSED-prep Public
Exploits written while preparing for the OSED exam