
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Post-exploitation tool for hiding processes from monitoring applications

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

In progress persistent download/upload/execution tool using Windows BITS.



iOS/macOS/Linux Remote Administration Tool

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Windows COM hijacking persistence tool with search, classic, Task Scheduler, and TreatAs modes. Available as .NET executable and Cobalt Strike BOF…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

Demonized Shell is an Advanced Tool for persistence in linux.

yet another AV killer tool using BYOVD

C# tool for establishing Windows persistence via multiple techniques including scheduled tasks, WMI events, startup folders, and registry hijacking,…

A Windows Remote Administration Tool in Visual Basic with UNC paths