
lsawhisper-bof
A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Windows memory-forensics and threat hunting tool that scans live process memory for malicious patterns, injection techniques, and reflectively loaded…

Shell Simulation over Net-SNMP with extend functionality

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Details about the Blind RCE issue(SPX-GC) in SPX-GC

A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for…

Windows Event Log Killer

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

Venom is a library that meant to perform evasive communication using stolen browser socket

Example of CVE-2024-24576 use case.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)