
DLLHijackHunter
Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Automated Persistence and Lateral Movement using GCP Patch Management

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Cross-Platform BOF Execution, and Scriptable Agents.

🇺🇦 Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

THorse is a RAT (Remote Administrator Trojan) Generator for Windows/Linux systems written in Python 3.

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Redirects EDR working folders using a Bind Filter (bindflt.sys) to bypass endpoint detection, corrupt EDR services, or replace with…

Permanently disable EDRs as local admin

PostShell - Post Exploitation Bind/Backconnect Shell


A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks