
PersistenceSniper
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A tool to transform Chromium browsers into a C2 Implant

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

macOS Initial Access Payload Generator

Source Code Management Attack Toolkit

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

Source Code Management Attack Toolkit

ExtensionHijack

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…