
Out-FINcodedCommand
POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

A simple bash based metasploit automation tool!

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Python based tool for generating Shellcode from PIC C

Remote Access Shell for Windows (based on cve-2022-30190)

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

A python based tool for exploiting and managing Android devices via ADB

A PowerShell based utility for the creation of malicious Office macro documents.

A unique technique to execute binaries from a password protected zip


XLL Phishing Tradecraft

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Python AV Evasion Tools

Playbook-based adversary simulation framework that compiles JSON-defined attack paths into position-independent shellcode payloads for validating…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…