
PoisonApple
CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

An information security preparedness tool to do adversarial simulation.

yet another AV killer tool using BYOVD

A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints

Attack and defend active directory using modern post exploitation adversary tradecraft activity

BlackLotus UEFI Windows Bootkit

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer