
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

fsociety Hacking Tools Pack – A Penetration Testing Framework

HERCULES is a special payload generator that can bypass antivirus softwares.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.


Powershell script for enumerating vulnerable DCOM Applications

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Tools and Techniques for Red Team / Penetration Testing

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.