
CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read
Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

Attack and defend active directory using modern post exploitation adversary tradecraft activity

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Hijacking valid driver services to load arbitrary (signed) drivers abusing native symbolic links and NT paths

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

PurpleSharp is a C# adversary simulation tool that executes adversary techniques with the purpose of generating attack telemetry in monitored Windows…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

An information security preparedness tool to do adversarial simulation.

Adversary Emulation Framework

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.