
HiveJack
This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/

Windows Privilege Escalation from User to Domain Admin.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Various tips & tricks

A new lightweight, hybrid routing mesh protocol for packet radios

My experiments in weaponizing Nim (https://nim-lang.org/)

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS