
MMSkillRisk
Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Simple (relatively) things allowing you to dig a bit deeper than usual.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

PoC-Malware-TTPs

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

macOS Initial Access Payload Generator

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

An information security preparedness tool to do adversarial simulation.

Adversary Emulation Framework

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)