
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…


An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

This repository is a collection of powershell functions every hacker should know

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Various tips & tricks

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

方便实用的CVE-2026-39363利用工具

Azure Post Exploitation Framework

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…


CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1


The Outlook HTML Leak Test Project

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit