
AD-Attack-Defense
Attack and defend active directory using modern post exploitation adversary tradecraft activity

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Bash post exploitation toolkit

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

Windows Remote Post Breach Tool via Telegram

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

PostShell - Post Exploitation Bind/Backconnect Shell

A host based IDS written in C# Targetted at Metasploit

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

This is a repository of resource about Malware techniques

Red Teaming & Pentesting checklists for various engagements

iOS/macOS/Linux Remote Administration Tool