
sliver
Adversary Emulation Framework

Adversary Emulation Framework

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Cloud-native C2 framework using cloud storage as dead-drop communication channel

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Trying to tame the three-headed dog.

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

A Python3 based C2 server to make life of red teamer a bit easier. The payload is capable to bypass all the known antiviruses and endpoints.

Stealthy DLL proxying implant for Microsoft Teams that injects AES-encrypted shellcode via unhooking techniques, providing persistent backdoor access…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

TDL4 style rootkit to spoof read/write requests to master boot record

An information security preparedness tool to do adversarial simulation.

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

CVE-2020-1048 bypass: binary planting PoC