
ThreadStackSpoofer
Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Thread Stack Spoofing - PoC for an advanced In-Memory evasion technique allowing to better hide injected shellcode's memory allocation from scanners…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

ROP-based sleep obfuscation to evade memory scanners

DLL Injection tool to unlock guest VMs

A python script developed to process Windows memory images based on triage type.

Main repository to pull all NCC Group Cisco ASA-related tool projects.

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Enumerate various traits from Windows processes as an aid to threat hunting

Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with…

Tool to make in memory man in the middle

A canary designed to minimize the impact from certain Ransomware actors

Cobalt Strike UDRL that performs advanced module stomping using VEH to intercept calls, unmap modules during sleep, and remap fresh modules to evade…

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

ML-assisted forensic analysis tool that automates memory, disk, and live system triage on Windows using Volatility 3, autorunsc, and sigcheck to…

A BOF designed to inspect processes memory and addresses