
sliver
Adversary Emulation Framework

Adversary Emulation Framework

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

An information security preparedness tool to do adversarial simulation.

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Simple (relatively) things allowing you to dig a bit deeper than usual.

macOS Initial Access Payload Generator

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

PoC-Malware-TTPs

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.