
GhostTrace
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

BlackLotus UEFI Windows Bootkit

This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs,…

Windows post-exploitation reconnaissance agent that collects system info, privileges, patches, defenses, network config, credentials, and persistence…

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.