
redteam-research
Collection of PoC and offensive techniques used by the BlackArrow Red Team

Collection of PoC and offensive techniques used by the BlackArrow Red Team

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

Repository to store exploits created by Assetnotes Security Research team

Exploits developped by Outflank B.V. team members

Exploit for CVE-2017-7269 targeting IIS 6.0 WebDAV remote code execution vulnerability. Enables buffer overflow exploitation on legacy Windows…

A collection of proof-of-concept exploit scripts written by the team at Redway Security for various CVEs.

Exploit for CVE-2019-19781 targeting Citrix ADC/NetScaler vulnerability. Provides automated exploitation for penetration testing and red team…

Python exploit for CVE-2017-5633 targeting Apache Struts2 remote code execution vulnerability. Designed for penetration testing and red team…

Python exploit script for CVE-2021-22986, targeting a remote code execution vulnerability in F5 BIG-IP devices. Provides URL-based exploitation for…

Exploit for CVE-2017-7269 targeting a remote code execution vulnerability in Microsoft IIS WebDAV. Designed for penetration testing and red team…

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

Pinjectra is a C/C++ OOP-like library that implements Process Injection techniques (with focus on Windows 10 64-bit)

Adaptive DLL hijacking / dynamic export forwarding

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

PoC Implementation of a fully dynamic call stack spoofer

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace