
Stuxnet
Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Autonomous Hacking Agent for Red Team

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

Educational proof-of-concept for PrintNightmare (CVE-2021-1675/34527) with simulated non-functional payload, attack flow analysis, MITRE mapping,…

An experimentation and research platform to investigate the interaction of automated agents in an abstract simulated network environments.

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

A personal RAG system for offensive security knowledge

PowerShell scripts for communicating with a remote host.

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.

Reproduction of cve-2025-53779-kerberos_bypass_reproduction

Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.