
moukthar
Android remote administration tool

Android remote administration tool

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Permanently disable EDRs as local admin

Remote operations commands implemented using Beacon Object Files

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Code developed to steal certain browser config files (history, preferences, etc)

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN