
CrystalPotato
Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Collection of VBA macro published in our twitter / blog

Bypass the Event Trace Windows(ETW) and unhook ntdll.



Windows 7 UAC Bypass Vulnerability in the Windows Script Host

Improved version of EKKO by @5pider that Encrypts only Image Sections

C2 redirector base on caddy

Execute PowerShell code at the antimalware-light protection level.

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Create Anti-Copy DRM Malware

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Purple-team telemetry & simulation toolkit.


Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs