
AD-Attack-Defense
Attack and defend active directory using modern post exploitation adversary tradecraft activity

Attack and defend active directory using modern post exploitation adversary tradecraft activity

Bash post exploitation toolkit

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

RedSails is a Python based post-exploitation project aimed at bypassing host based security monitoring and logging. DerbyCon 2017 Talk:…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

Windows Remote Post Breach Tool via Telegram

PostShell - Post Exploitation Bind/Backconnect Shell

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

A host based IDS written in C# Targetted at Metasploit

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

Scanner for the keyv/cacheable supply-chain attack: detects compromised npm packages, verifies payload hashes, and finds persistence implants in repo…

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

This is a repository of resource about Malware techniques