
AddUser-SAMR
Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

COM Windows Persistence Technique

PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.

Remote operations commands implemented using Beacon Object Files

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Automated Persistence and Lateral Movement using GCP Patch Management

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

In progress persistent download/upload/execution tool using Windows BITS.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

WORK IN PROGRESS. RAT written in C++ using Win32 API

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

choose and hide windows files/path from kernel space using this driver