

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Autonomous AI red team framework that chains reconnaissance, exploitation, and post-exploitation into a single pipeline, then triages findings,…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Android Remote Access Trojan

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

DejaVU - Open Source Deception Framework

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Abusing Azure services over C2

AzureRT - A Powershell module implementing various Azure Red Team tactics

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself