
slot2
UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

A little tool to play with Windows security

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

Decrypted content of eqgrp-auction-file.tar.xz

A tool to dump the login password from the current linux user

Various tips & tricks

My experiments in weaponizing Nim (https://nim-lang.org/)

Open-Source Remote Administration Tool For Windows C# (RAT)