
secret_handshake
A prototype malware C2 channel using x509 certificates over mTLS

A prototype malware C2 channel using x509 certificates over mTLS

Zero-trust anti-forensic HTTP client. Wipes secrets. Severs traces. CPR in a Stealth Tank. 👻

Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.

Curated collection of Cobalt Strike resources covering C2 profiles, BOFs, Aggressor scripts, evasion techniques, detection guides, and red team…

Collection of BYOVD proof-of-concept exploits that abuse vulnerable Windows kernel drivers to disable AV/EDR, with driver reverse engineering…

This map lists the essential techniques to bypass anti-virus and EDR

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

AV evading cross platform Backdoor and Crypter Framework with a integrated lightweight webUI

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Analysis and exploitation of CVE-2017-3066, a Java deserialization RCE in Adobe ColdFusion's BlazeDS library, with Suricata detection rules and…

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment

Obfuscated CVE-2024-6095 exploit script that uses random strings, advanced payloads, custom headers, and randomized delays to evade detection during…