
RedLine-Stealer-C2-Defender-Bypass-Payload-Analysis
"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

A tool to transform Chromium browsers into a C2 Implant

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

macOS Initial Access Payload Generator

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Source Code Management Attack Toolkit

Source Code Management Attack Toolkit

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

ExtensionHijack

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking