
OneDrive-UDC2
OneDrive as a covert C2 transport for Cobalt Strike

OneDrive as a covert C2 transport for Cobalt Strike

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…

Rapidly Search and Hunt through Windows Forensic Artefacts

Tool for embedding payloads into JPG/PNG format images, allowing to perform certain actions when opening them.

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Python ctypes wrapper for Event Tracing for Windows (ETW) enabling session control, event capture, and custom callbacks for security monitoring and…

Spam filtering and email processing framework with regex rules, statistical analysis, custom Lua plugins, and external blocklists for MTA integration.

DShield Sensor Log Collection with ELK

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

Draw.io libraries for threat modeling diagrams

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

AutoPoC Generator HoneyPoC

Automatically generated Sysmon parser for Azure Sentinel

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Runs custom filters on Elasticsearch and alerts on matches