
process-enumeration-stealth
Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

A tool that allows the generation of AMSI bypasses and the automatic obfuscation of PowerShell scripts using three different obfuscation methods.

:dart: Prevent RubberDucky (or other keystroke injection) attacks

HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate operating system…

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access (for Windows only)

Tool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Monitors Asterisk authentication logs and automatically bans IPs with repeated failed login attempts using iptables, with configurable thresholds and…

IPv6 analysis tool: the other side

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

Kernel-level iptables backdoor that accepts all packets with the RFC 3514 evil bit set, bypassing firewall rules. Includes in-tree and out-of-tree…

Obfuscate specific windows apis with different apis

ELF anti-reversing tool that overwrites section headers with nullbytes to prevent static analysis by disassemblers and debuggers, rendering functions…

A fake host that can be "managed" by Dell OMSA, getting you past the login screen.