
GoAT
🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Collection of tools that reflect the network dimension into Bloodhound's data

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

** DISCONTINUED ** C2 framework that uses Background Intelligent Transfer Service (BITS) as communication protocol and Direct Syscalls + Dinvoke for…

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

C# utility that uses WMI to run "cmd.exe /c netstat -n", save the output to a file, then use SMB to read and delete the file remotely

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…