
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis
Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…


Various tips & tricks


Bash post exploitation toolkit


Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11

Android remote administration tool

Assist reverse tcp shells in post-exploration tasks

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Attack and defend active directory using modern post exploitation adversary tradecraft activity