
owasp-cstg
Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Adversary Emulation Framework

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

Trying to tame the three-headed dog.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

A simple remote tool in C#.

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

LSTAR - CobaltStrike Translated to EN

poc for CVE-2025-24252 & CVE-2025-24132

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

CVE-2020-1048 bypass: binary planting PoC

Exploit for CVE-2025-54914 in Azure Networking, creating malicious routes with evasion, persistence, multi-target scanning, and reporting for…

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info
