
xspawn
Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Android remote administration tool

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

📦 Make security testing of K8s, Docker, and Containerd easier.

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Various tips & tricks

AdaptixC2 is a highly modular advanced redteam toolkit

Simple (relatively) things allowing you to dig a bit deeper than usual.

Red Teaming & Pentesting checklists for various engagements

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

A tool to abuse Exchange services

BlackLotus UEFI Windows Bootkit

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

A slightly more fun way to disable windows defender + firewall. (through the WSC api)