
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis
"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Source Code Management Attack Toolkit

macOS Initial Access Payload Generator

ExtensionHijack

A tool to transform Chromium browsers into a C2 Implant

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

Source Code Management Attack Toolkit

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation