
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A tool to transform Chromium browsers into a C2 Implant

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Source Code Management Attack Toolkit

Source Code Management Attack Toolkit

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.