- All languages
- Assembly
- Batchfile
- Boo
- C
- C#
- C++
- CSS
- Dart
- Dockerfile
- Emacs Lisp
- Go
- HCL
- HTML
- Haml
- Handlebars
- Java
- JavaScript
- Jinja
- Jupyter Notebook
- Lua
- Makefile
- Markdown
- Mathematica
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Pug
- Python
- REXX
- Roff
- Ruby
- Rust
- SCSS
- Scala
- Shell
- Svelte
- Swift
- TeX
- Text
- TypeScript
- Typst
- VBA
- Visual Basic
- Vue
- XSLT
- YAML
- YARA
- Zeek
- Zig
Starred repositories
A method of bypassing EDR's active projection DLL's by preventing entry point exection
PoC tool to coerce Windows hosts authenticate to other machines via the MS-RPRN RPC interface. This is possible via other protocols as well.
PowerShell rebuilt in C# for Red Teaming purposes
SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.
PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows environments
StandIn is a small .NET35/45 AD post-exploitation toolkit
Sandman is a NTP based backdoor for hardened networks.
SharpWMI is a C# implementation of various WMI functionality.
Self-developed tools for Lateral Movement/Code Execution
SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
Get file less command execution for lateral movement.
Kusto Query Language is a simple and productive language for querying Big Data.
DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments.
Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry
.NET Project for performing Authenticated Remote Execution
Self-hosted VirusTotal / MetaDefender wannabe with API, demo UI and Scanners running in Docker.