
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

A tool to transform Chromium browsers into a C2 Implant

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Source Code Management Attack Toolkit

Source Code Management Attack Toolkit

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking