
thc-tips-tricks-hacks-cheat-sheet
Various tips & tricks

Various tips & tricks

BlackLotus UEFI Windows Bootkit

iOS/macOS/Linux Remote Administration Tool

A tool to abuse Exchange services

LSTAR - CobaltStrike 综合后渗透插件

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

PowerSploit - A PowerShell Post-Exploitation Framework

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales,…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

CVE-2022-28672 Vulnerabilidad Foxit PDF Reader - UaF - RCE - JIT Spraying

Python logger with multiple features.

macOS persistence mechanism scanner with code signature verification and timeline tracking.

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…