
Red-Team-GOAD-Lab-Proxmox
Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

Build guide for Red Teaming home lab. GOAD lab setup in Proxmox and pfSense, Operator/C2 and Redirectors.

Automated adversary emulation (Caldera) against an AD lab to validate Sigma detection coverage and map results to MITRE ATT&CK.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Threadless Process Injection using remote function hooking.

C# Reflective loader for unmanaged binaries.

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Application-scoped Windows network brownouts in native C and BOF form

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

D/Invoke implementation in Nim

Simple (relatively) things allowing you to dig a bit deeper than usual.

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!

Collection of VBA macro published in our twitter / blog

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Load your driver like win32k.sys