
SharpGPOAbuse
SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

Source Code Management Attack Toolkit

ExtensionHijack

Source Code Management Attack Toolkit

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

macOS Initial Access Payload Generator

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines.…

A tool to transform Chromium browsers into a C2 Implant

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Spoofing the Windows 10 HDD/diskdrive serialnumber from kernel without hooking