
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…



Red Teaming & Pentesting checklists for various engagements

Win32 and Kernel abusing techniques for pentesters

This is a repository of resource about Malware techniques

macOS Initial Access Payload Generator

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

Various tips & tricks

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Pentest-Command

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

A pure python, post-exploitation, remote administration tool (RAT) for macOS / OS X.