
DLLHijackHunter
Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Permanently disable EDRs as local admin

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Automated Persistence and Lateral Movement using GCP Patch Management

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

PostShell - Post Exploitation Bind/Backconnect Shell

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks
