Skip to content
View sudonoodle's full-sized avatar

Sponsoring

@RedByte1337

Block or report sudonoodle

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
Python 6 Updated Nov 4, 2025

Cobalt Strike BOF for beacon/shellcode injection using fork & run technique with Draugr synthetic stack frames

C++ 111 17 Updated Nov 1, 2025

IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare

Python 219 14 Updated Oct 17, 2025

Windows protocol library, including SMB and RPC implementations, among others.

C# 560 61 Updated Nov 3, 2025

A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure.

Go 113 10 Updated Oct 29, 2025

Proof-of-concept implementation of AI-enabled postex DLLs

C++ 49 6 Updated Sep 10, 2025

A secure sandbox environment for malware developers and red teamers to test payloads against detection mechanisms before deployment. Integrates with LLM agents via MCP for enhanced analysis capabil…

YARA 1,203 133 Updated Sep 6, 2025

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

C 162 20 Updated Sep 3, 2025

An Ansible role for installing Cobalt Strike.

Shell 81 15 Updated Oct 14, 2025

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

HTML 150 17 Updated Jul 31, 2025

A delicious, but malicious SSL-VPN server 🌮

Python 252 31 Updated Oct 2, 2025

A small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike

C 169 25 Updated Oct 29, 2025

Local SYSTEM auth trigger for relaying - X

C 148 16 Updated Jul 23, 2025

Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus

C# 243 45 Updated Feb 23, 2022

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Python 1,228 165 Updated Mar 19, 2025

Quick and dirty dynamic redirect.rules generator

Python 166 45 Updated Oct 12, 2022

External C2 is a specification to allow third-party programs to act as a communication layer for Cobalt Strike’s Beacon payload.

C 13 Updated Jul 17, 2025

LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via Ludus for controlled testing.

PowerShell 330 23 Updated Sep 3, 2025

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

C++ 334 42 Updated Nov 19, 2024

Enable EFS service as low priv user (PE & BOF)

C 21 2 Updated Jul 6, 2025

Lightweight binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy. Designed for red team operations and ephemeral access into restricted environments using Tailscale’s …

Go 411 30 Updated Oct 3, 2025

A Model Context Protocol (MCP) server to converse with data in Bloodhound

Python 44 5 Updated Sep 8, 2025

A Python POC for CRED1 over SOCKS5

Python 159 13 Updated Oct 5, 2024
Python 123 22 Updated Jul 7, 2025

Beacon Object File (BOF) for dumping certificates (and, when possible, private keys) on Windows

C 11 Updated Jun 2, 2025

The most extensive collection of BOFs (Beacon Object Files) tailored for Red Teams using C++23

C++ 15 4 Updated Jun 19, 2025

Collection of Beacon Object Files (BOF) for Cobalt Strike

C 650 93 Updated Aug 15, 2025

Cobalt Strike BOF to fetch tokens from Token Broker cache

C++ 2 Updated May 18, 2025
Next