
TokenFlare
Serverless AITM Simulation Framework for Entra ID and M365

Serverless AITM Simulation Framework for Entra ID and M365

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

Crystal Palace Evasion kit for Sliver

Like Envoy xDS, but for eBPF filters

Evades AV and sandboxes on Windows using anti-sandbox checks, ntdll unhooking, dynamic API resolution, and multi-layer shellcode obfuscation…

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

Remove API hooks from a Beacon process.

Memory API proxy via signed mozglue.dll

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

A program for testing WAF functionality

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Header bypass for CVE-2025-55182 (React Server Components RCE).

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

Exploit for Apache Unomi pre-auth RCE (CVE-2020-13942) with a Suricata detection rule for identifying exploitation attempts.

Red Team utilities for setting up CWP CentOS 7 payload & reverse shell (Red Team 9 - CW2023)