
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

PowerSploit - A PowerShell Post-Exploitation Framework

C# based tool which automates the process of discovering and exploiting DLL Hijacks in target binaries. The Hijacked paths discovered can later be…

A rootkit for ubuntu-16.04.6 (Linux 4.4). Can hide a process, give root access and hide itself

Educational deep dive into macOS app bundles, plist files, and launchd process behavior, with offensive security notes on packaging payloads as .app…

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

CobaltWhispers is an aggressor script that utilizes a collection of Beacon Object Files (BOF) for Cobalt Strike to perform process injection,…

Red Teaming & Pentesting checklists for various engagements

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

Win32 and Kernel abusing techniques for pentesters

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Dropping a powershell script at %HOMEPATH%\Documents\WindowsPowershell\ , that contains the implant's path , and whenever powershell process is…

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

Hides Process From Task Manager Using NT API Hooking (NtQuerySystemInformation)

RedPeanut is a small RAT developed in .Net Core 2 and its agent in .Net 3.5 / 4.0.