
fakelogonscreen
Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

Demo project how to bypass the disable_functions security control of PHP on Linux

A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.

My experiments in weaponizing Nim (https://nim-lang.org/)

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Proof-of-concept exploit for CVE-2020-0728 demonstrating local privilege escalation via Windows TrustedInstaller COM service abuse to bypass file…

In progress persistent download/upload/execution tool using Windows BITS.

Covert backdoor transmission tool using 802.11 probe request and beacon frames for isolated network attacks. Delivers payloads via HID devices,…

PowerShell tool for red teamers that clears execution evidence by stopping event logging, removing file and registry artifacts, and saving timestamps…

Decrypted content of eqgrp-auction-file.tar.xz

Android Remote Access Trojan

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.