
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

An egress firewall for untrusted workloads.

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.

PowerSploit - A PowerShell Post-Exploitation Framework

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).

More examples using the Impacket library designed for learning purposes.

C# Tool to interact with MS Exchange based on MS docs

A standalone Blind XSS Script.

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

A prototype malware C2 channel using x509 certificates over mTLS

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Default Detections for EDR

This repository is a collection of powershell functions every hacker should know

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…