
ADOKit
Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Automated Attack Simulation in the Cloud, complete with detection use cases.

Go-based proof-of-concept exploit for CVE-2023-5044 in ingress-nginx, enabling authenticated remote command execution by creating crafted Kubernetes…

Cloud-based attack emulation framework for executing offensive techniques and generating repeatable detection samples across AWS and GCP via a UI or…

CVE-2023-23192

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Red Team K8S Adversary Emulation Based on kubectl

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

A proof of concept demonstrating the use of Google Drive for command and control.