
GC2-sheet
GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

Identifies the bytes that Microsoft Defender flags on.

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

A Linux version of the ProcDump Sysinternals tool

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office RCE) with a hosted server for DLL payload delivery, based on…

Identifies the bytes that Microsoft Defender / AMSI Consumer flags on.

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

A free utility that finds malware, adware and other security threats

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

Red Team C code repo

Incident Response & Digital Forensics Debugging Extension

An strace-like program for the Windows 'native' API

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

Collection of extracted Microsoft Defender data for security research purposes

User-friendly Microsoft Windows Debugger for Malware Analysts.

Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Detects CanaryTokens in Office docs and PDFs (docx, xlsx, pptx, pdf) without triggering alerts