
macos-collector
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Permanently disable EDRs as local admin

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…


PostShell - Post Exploitation Bind/Backconnect Shell

Automated Persistence and Lateral Movement using GCP Patch Management

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks