
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Python library for adversarial machine learning security, enabling red and blue teams to run evasion, poisoning, extraction, and inference attacks…

C2 profile for Mythic tunneling encrypted peer-to-peer agent traffic through IEEE 802.1AB LLDP Organizationally Specific TLVs for covert Layer 2…

Local white-box gradient attacks for open-weight LLMs: GCG/PEZ suffix search, layer saliency, weight snapshots, and rank-1 suffix-to-delta fitting…

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

PoCs and tools for investigation of Windows process execution techniques

Purple Team Exercise Framework

Lifetime AMSI bypass

Loading Remote AES Encrypted PE in memory , Decrypted it and run it

Purpleteam scripts simulation & Detection - trigger events for SOC detections

Detect EDR's exceptions by inspecting processes' loaded modules

Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.

Bypass the Event Trace Windows(ETW) and unhook ntdll.

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging

A Bumblebee-inspired Crypter

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…